CVE-2025-59178 PUBLISHED

Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability

Assigner: ERIC
Reserved: 10.09.2025 Published: 27.07.2026 Updated: 27.07.2026

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.8

Product Status

Vendor Ericsson
Product Packet Core Controller (PCC)
Versions Default: unaffected
  • affected from 0 to 1.39 (excl.)

Credits

  • Spark NZ finder
  • Radu Balaci and Meghna Patel from Bell Mobility (Canada) finder

References

Problem Types

  • CWE-497 Exposure of sensitive system information to an unauthorized control sphere CWE