Skip to content
EricssonCVE-2025-59180

Ericsson Packet Core Controller (PCC): hard-coded credentials

Medium5.1CVE-2025-59180 · Published Jul 27, 2026 · updated Jul 28, 2026

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

Ericsson advisory

Affected versions

PackageAffectedFixed in
Packet Core Controller (PCC)
Product
< 1.381.38
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-798

More Ericsson advisories

All Ericsson

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.