PatchSiren

Ericsson CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Ericsson CVE published 2026-07-27

CVE-2025-59181

CVE-2025-59181 is a directory traversal vulnerability in the Configuration Management of Ericsson Packet Core Controller (PCC) versions prior to 1.39. This vulnerability could allow an attacker to change directory permissions, potentially denying access to legitimate users. The CVE record was published on 2026-07-27T15:16:46.300Z and has not been modified since then. Administrators and security teams shou [truncated]

MEDIUM Ericsson CVE published 2026-07-27

CVE-2025-59180

The Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster and knowledge of the hardcoded credential can read alarm and alert information. This vulnerability has a medium severity level with a CVSS score of 5.1. Users of PCC should review their deployments and apply necessary updates.

MEDIUM Ericsson CVE published 2026-07-27

CVE-2025-59178

A MEDIUM severity vulnerability was found in Ericsson Packet Core Controller (PCC) versions prior to 1.39. The Exposure of Sensitive System Information vulnerability in Configuration Management allows an attacker to enumerate other users on the system. This issue affects Ericsson Packet Core Controller (PCC) versions prior to 1.39, and administrators should be aware of the potential risks associated with [truncated]

MEDIUM Ericsson CVE published 2026-07-27

CVE-2025-59177

The CVE record for CVE-2025-59177 was published on 2026-07-27T15:16:45.893Z and has not been modified since then. The NVD entry provides a CVSS score of 6.8, indicating medium severity. Ericsson Packet Core Controller (PCC) versions prior to 1.39 are affected by a vulnerability in Configuration Management, allowing crafted commands to reveal system secrets through error messages. Users should review and a [truncated]

HIGH Ericsson CVE published 2026-07-27

CVE-2025-59172

The CVE-2025-59172 vulnerability is an Improper Neutralization of Special Elements issue in Ericsson Packet Core Controller (PCC) versions prior to 1.38. This HIGH severity vulnerability, with a CVSS score of 8.5, allows an attacker to execute arbitrary code as root. The vulnerability was published on 2026-07-27T15:16:45.017Z. Administrators and security teams responsible for Ericsson Packet Core Controll [truncated]

HIGH Ericsson CVE published 2026-06-05

CVE-2025-59174

CVE-2025-59174 is a HIGH severity vulnerability in Ericsson's Packet Core Controller (PCC). Versions prior to 1.39 are affected. An attacker can cause service degradation by sending a large volume of specially crafted messages. The vulnerability was published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2025-59174) on 2026-06-05 and last modified on 2026-06-08. For more information, see the [NVD deta [truncated]

HIGH Ericsson CVE published 2026-06-05

CVE-2026-25659

CVE-2026-25659 is a HIGH severity vulnerability in Ericsson's Packet Core Gateway (PCG). Versions prior to 1.30 are affected by an Improper Handling of Missing Values (CWE-230) vulnerability. An attacker can cause service degradation by continuously sending specially crafted messages. The impact persists as long as the attack continues, but the system recovers when the attack stops. The CVSS score for thi [truncated]

HIGH Ericsson CVE published 2026-06-05

CVE-2026-25658

CVE-2026-25658 is a HIGH-severity vulnerability in Ericsson's Packet Core Gateway (PCG) versions prior to 1.30. The issue is an Improper Handling of Missing Values (CWE-230) that can cause service degradation when an attacker continuously sends specially crafted messages. The impact persists as long as the attack continues but the system recovers once the attack stops.

HIGH Ericsson CVE published 2026-06-05

CVE-2026-25657

CVE-2026-25657 is a HIGH severity vulnerability in Ericsson Packet Core Gateway (PCG) versions prior to 1.30. An attacker can cause service degradation by continuously sending specially crafted messages. The impact persists as long as the attack continues, but the system recovers when the attack stops.