PT-2026-64918 · Ericsson · Packet Core Controller

·

CVE-2025-59180

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v4.0

5.1

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ericsson Packet Core Controller (PCC) versions prior to 1.38
Description The alarm system contains hardcoded credentials. An attacker with cluster access and knowledge of these credentials can read alarm and alert information.
Recommendations Update to version 1.38 or later.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59180

Affected Products

Packet Core Controller