Skip to content
EricssonCVE-2025-59177

Ericsson Packet Core Controller (PCC): information disclosure in errors

Medium6.8CVE-2025-59177 · Published Jul 27, 2026 · updated Jul 28, 2026

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.

Ericsson advisory

Affected versions

PackageAffectedFixed in
Ericsson Packet Core Controller (PCC)
Product
< 1.391.39
Details and references
CVSS 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-209

More Ericsson advisories

All Ericsson

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.