CVE-2025-59178

Summary

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

Affected Software

VendorProductVersion RangeStatus
EricssonPacket Core Controller (PCC)0 < 1.39affected

Weaknesses

  • CWE-497: CWE-497 Exposure of sensitive system information to an unauthorized control sphere

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References