PT-2026-64916 · Ericsson · Packet Core Controller
CVSS v4.0
6.8
Medium
| Vector | AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Ericsson Packet Core Controller (PCC) versions prior to 1.39
Description
A flaw in Configuration Management allows an attacker to execute specifically crafted commands, which can lead to the disclosure of system secrets via error messages.
Recommendations
Update to version 1.39 or later.
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Packet Core Controller