CVE-2024-53828 PUBLISHED

Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerability

Assigner: ERIC
Reserved: 22.11.2024 Published: 01.04.2026 Updated: 01.04.2026

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 5.3

Product Status

Vendor Ericsson
Product Packet Core Controller (PCC)
Versions Default: affected
  • affected from 0 to 1.38 (excl.)

Credits

  • The UK’s National Cyber Security Centre (NCSC) finder
  • The UK Telecoms Lab (UKTL) finder

References

Problem Types

  • CWE-228 CWE