CVE-2025-59174 PUBLISHED

Assigner: ERIC
Reserved: 10.09.2025 Published: 05.06.2026 Updated: 05.06.2026

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor Ericsson
Product Packet Core Controller
Versions Default: unaffected
  • affected from 0 to 1.39 (excl.)

Credits

  • The UK Telecoms Lab (UKTL) finder
  • The UK’s National Cyber Security Centre (NCSC) finder

References

Problem Types

  • CWE-228: Improper Handling of Syntactically Invalid Structure CWE