CVE-2025-59180

Summary

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

Affected Software

VendorProductVersion RangeStatus
EricssonPacket Core Controller (PCC)0 < 1.38affected

Weaknesses

  • CWE-798: CWE-798

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References