Description
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.
Published: 2026-07-27
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a hard‑coded credential in the monitoring component of Ericsson Packet Core Controller, allowing an attacker to read alarm and alert data once cluster access is established. This flaw is classified as CWE‑798 and results in confidentiality compromise of operational network information.

Affected Systems

Ericsson Packet Core Controller (PCC) versions prior to 1.38 are affected; the advisory does not list later versions, so it is inferred that newer releases do not contain the vulnerability.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. The EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV, implying no known public exploitation. An attacker must already have cluster visibility and knowledge of the embedded credential, limiting the attack to users with legitimate cluster access; however, once attained, the breach can expose critical alarm information.

Generated by OpenCVE AI on August 3, 2026 at 17:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Ericsson Packet Core Controller version 1.38 or later to eliminate the hard‑coded credential.
  • If an update is not immediately possible, configure the alarm system to use a unique, strong password instead of the default value.
  • Enforce strict cluster access controls and least‑privilege policies to prevent unauthorized users from obtaining the hard‑coded credential.

Generated by OpenCVE AI on August 3, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ericsson
Ericsson packet Core Controller
Vendors & Products Ericsson
Ericsson packet Core Controller

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.
Title Use of Hard-coded Credentials Vulnerability
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ericsson Packet Core Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: ERIC

Published:

Updated: 2026-07-27T15:08:17.243Z

Reserved: 2025-09-10T13:24:49.362Z

Link: CVE-2025-59180

cve-icon Vulnrichment

Updated: 2026-07-27T15:08:13.186Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:16:46.170

Modified: 2026-07-28T16:17:16.127

Link: CVE-2025-59180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials