Impact
The vulnerability is a hard‑coded credential in the monitoring component of Ericsson Packet Core Controller, allowing an attacker to read alarm and alert data once cluster access is established. This flaw is classified as CWE‑798 and results in confidentiality compromise of operational network information.
Affected Systems
Ericsson Packet Core Controller (PCC) versions prior to 1.38 are affected; the advisory does not list later versions, so it is inferred that newer releases do not contain the vulnerability.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. The EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV, implying no known public exploitation. An attacker must already have cluster visibility and knowledge of the embedded credential, limiting the attack to users with legitimate cluster access; however, once attained, the breach can expose critical alarm information.
OpenCVE Enrichment