CVE-2025-59180
Received Received - Intake

Hardcoded Credential in Ericsson Packet Core Controller

Vulnerability report for CVE-2025-59180, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Ericsson

Description

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ericsson packet_core_controller to 1.38 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Ericsson Packet Core Controller (PCC) versions before 1.38 have a hardcoded credential flaw in the alarm system. An attacker with cluster access and knowledge of the hardcoded credential can read alarm and alert information.

Detection Guidance

To detect this vulnerability, check for the presence of Ericsson Packet Core Controller (PCC) versions prior to 1.38. Verify if hardcoded credentials exist in the alarm system by inspecting configuration files or system logs for default or known credentials.

Impact Analysis

An attacker could gain unauthorized access to sensitive alarm and alert data, potentially exposing operational or security-related information from the network.

Compliance Impact

The vulnerability involves hardcoded credentials in Ericsson Packet Core Controller (PCC) versions prior to 1.38, allowing attackers to read alarm and alert information. This could lead to unauthorized access to sensitive data, potentially violating confidentiality requirements in GDPR and HIPAA.

Mitigation Strategies

Upgrade Ericsson Packet Core Controller (PCC) to version 1.38 or later to remove the hardcoded credentials. Ensure all default credentials are changed and restrict access to the cluster to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-59180. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart