CVE-2025-59177
Received Received - Intake

Configuration Management Command Injection in Ericsson Packet Core Controller

Vulnerability report for CVE-2025-59177, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Ericsson

Description

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ericsson packet_core_controller to 1.39 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-209 The product generates an error message that includes sensitive information about its environment, users, or associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Ericsson Packet Core Controller (PCC) versions before 1.39 allows an attacker to send specially crafted commands that exploit error messages to reveal system secrets.

Detection Guidance

This vulnerability involves Ericsson Packet Core Controller (PCC) versions prior to 1.39. Detection requires checking the installed PCC version and monitoring for unusual command execution or error messages that expose system secrets. No specific commands are provided in the available context.

Impact Analysis

An attacker could gain access to sensitive system information, potentially leading to further exploitation of the network or unauthorized access to confidential data.

Compliance Impact

The vulnerability allows attackers to reveal system secrets through error messages, which could lead to unauthorized access to sensitive data. This may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data privacy) by exposing confidential information.

Mitigation Strategies

Upgrade Ericsson Packet Core Controller (PCC) to version 1.39 or later to address the Configuration Management vulnerability. Monitor error messages for suspicious command execution attempts and restrict access to system secrets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-59177. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart