CVE-2025-59181
Received Received - Intake

Directory Traversal in Ericsson Packet Core Controller

Vulnerability report for CVE-2025-59181, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: Ericsson

Description

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ericsson packet_core_controller to 1.39 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-35 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a directory traversal issue in Ericsson Packet Core Controller (PCC) versions before 1.39. It allows an attacker to change directory permissions, which could block legitimate users from accessing the system.

Detection Guidance

This vulnerability affects Ericsson Packet Core Controller (PCC) versions prior to 1.39. To detect it, check the installed PCC version using system commands like 'show version' or 'rpm -qa | grep ericsson' on Linux-based systems. If the version is below 1.39, the system is vulnerable.

Impact Analysis

If exploited, this vulnerability could deny access to legitimate users, potentially disrupting network services and operations that rely on the PCC.

Compliance Impact

The vulnerability may lead to unauthorized access or denial of service, potentially violating data integrity and availability requirements in GDPR and HIPAA. However, specific compliance impacts are not detailed in the provided CVE information.

Mitigation Strategies

Immediately upgrade Ericsson Packet Core Controller (PCC) to version 1.39 or later to address the directory traversal vulnerability in Configuration Management.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-59181. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart