Impact
The Ericsson Packet Core Controller (PCC) suffers from a directory traversal flaw located in its configuration management module. Exploiting this vulnerability allows an attacker to manipulate file paths in order to change directory permissions, effectively denying legitimate users access to crucial configuration data. Because the flaw directly alters permissions, the principal risk is service disruption and potential privilege escalation within the PCC system. This weakness corresponds to CWE‑35.
Affected Systems
Ericsson Packet Core Controller versions prior to 1.39 are affected. All releases before 1.39 contain the directory traversal vulnerability in configuration management.
Risk and Exploitability
The CVSS score is 4.8, indicating moderate severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalogue. The description implies that an attacker would need to gain some local or administrative access to the PCC’s configuration interface; the exact attack vector (local vs. remote) is not explicitly stated and is thus inferred from the nature of the flaw.
OpenCVE Enrichment