CVE-2024-25008: Ericsson Controller 6610
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated privileges for example a valid OAM user having the system administrator role to exploit the vulnerability.
Affected products
- Ericsson Controller 6610: before 24.q2 (fixed in 24.q2)
- Ericsson Ericsson Ran Compute Basebands All Bb Variants: before 24.Q2 (fixed in 24.Q2)
- Ericsson Ran Compute: before 24.q2 (fixed in 24.q2)
- Ericsson Site Controller 6610: before 24.Q2 (fixed in 24.Q2)
Published 2024-08-16. Last modified 2026-06-17.