Skip navigation
Previous searches
    Suggested searches

      Security Bulletin – Ericsson Packet Core Controller (PCC), July 2026

      Summary:

      Ericsson has released updates for Ericsson Packet Core Controller (PCC) to address security issues that, if exploited, may lead to escalation of privileges, arbitrary code execution, information disclosure and/or denial of service.

      Vulnerability description:

      This section summarizes the vulnerability issue and potential impact that this security update addresses.

      CVE-2025-59172 - Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.

      CVSS Base Score: 8.5
      Severity: High
      CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
      Weakness Type: CWE-78: Improper Neutralization of Special Elements used in an OS Command

      CVE-2025-59177 - Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.

      CVSS Base Score: 6.8
      Severity:  Medium
      CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N 
      Weakness Type: CWE-209: Generation of Error Message Containing Sensitive Information

      CVE-2025-59178 - Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

      CVSS Base Score: 4.8
      Severity:  Medium
      CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
      Weakness Type: CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere

      CVE-2025-59180 - Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

      CVSS Base Score: 5.1
      Severity:  Medium
      CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
      Weakness Type: CWE-798: Use of Hard-coded Credentials

      CVE-2025-59181 - Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.

      CVSS Base Score: 4.8
      Severity:  Medium
      CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
      Weakness Type: CWE-35: Path Traversal

      Security update:

      The following table lists the Ericsson products affected, versions affected, and the updated version that includes this security update.

      To protect your system, download and install the updated version.

      CVE Addressed Product Name Affected Versions Updated Versions
      CVE-2025-59172 Packet Core Controller All versions prior to 1.38 1.38
      CVE-2025-59177 Packet Core Controller All versions prior to 1.39 1.39
      CVE-2025-59178 Packet Core Controller All versions prior to 1.39 1.39
      CVE-2025-59180 Packet Core Controller All versions prior to 1.38 1.38
      CVE-2025-59181 Packet Core Controller All versions prior to 1.39 1.39

      Acknowledgement:

      Ericsson thanks following people/organization for reporting these issues to us:

      • Spark NZ
      • Radu Balaci and Meghna Patel from Bell Mobility (Canada)

      Additional information:

      • Ericsson severity assessment of a vulnerability is based on an average of risk across a diverse set of installed systems and may not represent the true risk to your organization. We recommend evaluating the risk to your specific configuration.
      • If you have any questions regarding this bulletin, please reach out to your local Ericsson support representative, for more information see Customer Support page.
      • Learn more about the vulnerability management process followed by the Ericsson Product Security Incident Response Team (PSIRT), see Ericsson PSIRT page.

      Revision history:

      Revision Date Description
      1.0 July 24, 2026 Initial Release

      © Ericsson AB 2026. All rights reserved. No part of this message may be reproduced in any form without the written permission of the copyright owner. The contents of this document are subject to revision without notice due to continued progress in methodology, design and manufacturing. Ericsson shall have no liability for any error or damage of any kind resulting from the use of this message. For questions, please contact Ericsson Local Support or connect with us on the Omni Network Channel section of My Ericsson. Visit us at Support User Preferences to unsubscribe.