Skip to content
EricssonCVE-2025-59178

Ericsson Packet Core Controller (PCC): system information exposure

Medium4.8CVE-2025-59178 · Published Jul 27, 2026 · updated Jul 28, 2026

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

Ericsson advisory

Affected versions

PackageAffectedFixed in
Packet Core Controller (PCC)
Product
< 1.391.39
Details and references
CVSS 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-497

More Ericsson advisories

All Ericsson

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.