PatchSiren

Ericsson CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Ericsson CVE published 2026-06-05

CVE-2025-59174

CVE-2025-59174 is a HIGH severity vulnerability in Ericsson's Packet Core Controller (PCC). Versions prior to 1.39 are affected. An attacker can cause service degradation by sending a large volume of specially crafted messages. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2025-59174) on 2026-06-05 and last modified on 2026-06-08. For more information, see the [NVD deta [truncated]

HIGH Ericsson CVE published 2026-06-05

CVE-2026-25659

CVE-2026-25659 is a HIGH severity vulnerability in Ericsson's Packet Core Gateway (PCG). Versions prior to 1.30 are affected by an Improper Handling of Missing Values (CWE-230) vulnerability. An attacker can cause service degradation by continuously sending specially crafted messages. The impact persists as long as the attack continues, but the system recovers when the attack stops. The CVSS score for thi [truncated]

HIGH Ericsson CVE published 2026-06-05

CVE-2026-25658

CVE-2026-25658 is a HIGH-severity vulnerability in Ericsson's Packet Core Gateway (PCG) versions prior to 1.30. The issue is an Improper Handling of Missing Values (CWE-230) that can cause service degradation when an attacker continuously sends specially crafted messages. The impact persists as long as the attack continues but the system recovers once the attack stops.

HIGH Ericsson CVE published 2026-06-05

CVE-2026-25657

CVE-2026-25657 is a HIGH severity vulnerability in Ericsson Packet Core Gateway (PCG) versions prior to 1.30. An attacker can cause service degradation by continuously sending specially crafted messages. The impact persists as long as the attack continues, but the system recovers when the attack stops.