EricssonCVE-2025-59178
Ericsson Packet Core Controller (PCC): system information exposure
Medium4.8CVE-2025-59178 · Published Jul 27, 2026 · updated Jul 28, 2026
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Packet Core Controller (PCC) Product | < 1.39 | 1.39 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-497
More Ericsson advisories
All Ericsson| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | Ericsson CodeChecker: denial of service | Medium5.5 | 6.28.3 |
| Aug 26 | Ericsson CodeChecker: improper access control | Low1.2 | 6.28.3 |
| Jul 27 | Ericsson Packet Core Controller (PCC): hard-coded credentials | Medium5.1 | 1.38 |
| Jul 27 | Ericsson Packet Core Controller (PCC): path traversal | Medium4.8 | 1.39 |
| Jul 27 | Ericsson Packet Core Controller (PCC): code execution | High8.5 | 1.38 |
| Jul 27 | Ericsson Packet Core Controller (PCC): information disclosure in errors | Medium6.8 | 1.39 |