CVE-2025-59178
4.8
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ericsson | Packet Core Controller (PCC) | 0 < 1.39 | affected |
Weaknesses
- CWE-497: CWE-497 Exposure of sensitive system information to an unauthorized control sphere
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.