NVD disclosure day

Published threat advisories for April 16, 2025

CVE advisoryKnown Exploit

CVE-2025-32433

Erlang/OTP SSH Server Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Erlang/OTP's SSH server could allow unauthorized remote code execution. This impacts organizations using affected systems, potentially exposing sensitive data and business operations to risk. Immediate remediation is advised.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-31201

Apple Products Arbitrary Read and Write Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Apple products including iOS, iPadOS, macOS, tvOS, and visionOS are affected by a vulnerability that allows an attacker to bypass Pointer Authentication. This could lead to unauthorized access and manipulation of data. While sophisticated attacks against targeted individuals have been reported, the business risk can be

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-31200

Apple Device Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A memory corruption vulnerability in Apple operating systems can allow for code execution when processing a specially crafted audio stream. Reports indicate sophisticated attacks have exploited this issue against targeted individuals on older iOS versions. Organizations should apply vendor updates to mitigate risk.

• CISA KEV