Description
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.
Published: 2026-07-27
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ericsson Packet Core Controller (PCC) suffers from a directory traversal flaw located in its configuration management module. Exploiting this vulnerability allows an attacker to manipulate file paths in order to change directory permissions, effectively denying legitimate users access to crucial configuration data. Because the flaw directly alters permissions, the principal risk is service disruption and potential privilege escalation within the PCC system. This weakness corresponds to CWE‑35.

Affected Systems

Ericsson Packet Core Controller versions prior to 1.39 are affected. All releases before 1.39 contain the directory traversal vulnerability in configuration management.

Risk and Exploitability

The CVSS score is 4.8, indicating moderate severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalogue. The description implies that an attacker would need to gain some local or administrative access to the PCC’s configuration interface; the exact attack vector (local vs. remote) is not explicitly stated and is thus inferred from the nature of the flaw.

Generated by OpenCVE AI on August 3, 2026 at 17:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Ericsson PCC to version 1.39 or later, which removes the vulnerable configuration management code.
  • Restrict the configuration management interface to authenticated users with the minimal privileges required, enforcing strong password or certificate policies.
  • Audit and correct permissions on all critical configuration directories to detect and remediate any unauthorized changes.

Generated by OpenCVE AI on August 3, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ericsson
Ericsson packet Core Controller
Vendors & Products Ericsson
Ericsson packet Core Controller

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.
Title Path traversal Vulnerability
Weaknesses CWE-35
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Ericsson Packet Core Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: ERIC

Published:

Updated: 2026-07-27T15:07:53.787Z

Reserved: 2025-09-10T13:24:49.362Z

Link: CVE-2025-59181

cve-icon Vulnrichment

Updated: 2026-07-27T15:07:47.238Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:16:46.300

Modified: 2026-07-28T16:17:16.127

Link: CVE-2025-59181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:30:17Z

Weaknesses
  • CWE-35

    Path Traversal: '.../...//'