Description
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
Published: 2026-07-27
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CWE‑497 exposure of sensitive system information in the configuration management component of Ericsson Packet Core Controller. An attacker who can interact with the configuration interface can enumerate other local users, revealing potentially identifying information. This does not allow code execution, but it increases the attack surface for credential gathering and lateral movement. Based on the description, it is inferred that the attacker must first gain access to the configuration interface, which may be protected by authentication or network segmentation.

Affected Systems

Ericsson Packet Core Controller (PCC) releases prior to version 1.39 are affected. The vulnerability resides in the configuration management functionality common to all earlier builds.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, and the EPSS score of less than 1% shows a very low exploitation probability, so deployment likelihood remains low. Based on the description, it is inferred that attackers must access the configuration interface to perform enumeration, and the likely attack vector is through a compromised configuration session or a misconfigured network service providing access to the interface. Attackers would need some level of access to PCC’s configuration management interface, which may be protected by network segmentation and authentication; if these controls are lax, enumeration could be performed over the local network or via remote management interfaces. No public exploit or proof‑of‑concept is documented, so the risk depends largely on the environment’s exposure of the configuration interface.

Generated by OpenCVE AI on August 3, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Packet Core Controller to version 1.39 or newer to eliminate the identified information disclosure.
  • Restrict access to the PCC configuration management interface by enforcing strict network segmentation and strong authentication, limiting exposure to only authorized personnel.
  • Monitor system logs for user enumeration attempts and investigate any suspicious activity related to the configuration interface.

Generated by OpenCVE AI on August 3, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ericsson
Ericsson packet Core Controller
Vendors & Products Ericsson
Ericsson packet Core Controller

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
Title Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability
Weaknesses CWE-497
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ericsson Packet Core Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: ERIC

Published:

Updated: 2026-07-27T15:06:03.400Z

Reserved: 2025-09-10T13:24:49.361Z

Link: CVE-2025-59178

cve-icon Vulnrichment

Updated: 2026-07-27T15:05:56.578Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:16:46.020

Modified: 2026-07-28T16:17:16.127

Link: CVE-2025-59178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere