PatchSiren cyber security CVE debrief
CVE-2025-59178 Ericsson CVE debrief
A MEDIUM severity vulnerability was found in Ericsson Packet Core Controller (PCC) versions prior to 1.39. The Exposure of Sensitive System Information vulnerability in Configuration Management allows an attacker to enumerate other users on the system. This issue affects Ericsson Packet Core Controller (PCC) versions prior to 1.39, and administrators should be aware of the potential risks associated with this vulnerability.
- Vendor
- Ericsson
- Product
- Packet Core Controller (PCC)
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-07-27
Who should care
Administrators and security teams responsible for Ericsson Packet Core Controller (PCC) versions prior to 1.39 should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing and updating Configuration Management settings to prevent enumeration of other users on the system.
Technical summary
The CVE-2025-59178 vulnerability has a CVSS score of 4.8 and is classified as MEDIUM severity. It affects Ericsson Packet Core Controller (PCC) versions prior to 1.39 and allows an attacker to enumerate other users on the system through Configuration Management. The vulnerability is related to the Exposure of Sensitive System Information.
Defensive priority
Apply vendor-provided patches or updates to Ericsson Packet Core Controller (PCC) versions prior to 1.39 to mitigate the Exposure of Sensitive System Information vulnerability. Monitor system logs for potential exploitation attempts and review compensating controls for exposed systems while remediation is scheduled and verified. Ensure that Configuration Management settings are reviewed and updated to prevent enumeration of other users on the system. Consider implementing additional security measures to detect and prevent potential attacks. Verify the accuracy of the information provided and perform additional verification tasks as necessary to ensure the security of the system. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Consider asset inventory and rollback/change windows as part of the remediation process if necessary and applicable to the environment and exposure context. These actions are recommended based on the available information and should be adapted to the specific organizational needs and context. The prioritization of these actions may vary depending on the specific circumstances and risk assessment of the affected systems and deployments. It is essential to stay informed about the latest developments and updates related to this vulnerability and to adjust the defensive strategies accordingly. The implementation of these recommendations should be done in accordance with organizational policies and procedures. The goal is to minimize the risk associated with this vulnerability and to ensure the security and integrity of the affected systems and data. The recommendations provided are based on the information available at the time of the analysis and may need to be adjusted as new information becomes available. It is crucial to continuously monitor the situation and to be prepared to act
Recommended defensive actions
- Apply patches or updates to Ericsson Packet Core Controller (PCC) versions prior to 1.39
- Review and update Configuration Management settings to prevent enumeration of other users on the system
- Monitor system logs for potential exploitation attempts
Evidence notes
The CVE record was published on 2026-07-27T15:16:46.020Z and was last modified on 2026-07-27T16:16:59.250Z. The NVD entry is currently in the 'Received' status. The information provided is based on the available data and may not be exhaustive. Further verification is recommended to ensure accurate understanding of the vulnerability.
Official resources
-
CVE-2025-59178 CVE record
CVE.org
-
CVE-2025-59178 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
85b1779b-6ecd-4f52-bcc5-73eac4659dcf
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T15:16:46.020Z and has not been modified since then. The NVD entry is currently Received.