CVE-2025-59180: Ericsson Packet Core Controller Pcc

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

Affected products

  • Ericsson Packet Core Controller Pcc: before 1.38 (fixed in 1.38)

Published 2026-07-27. Last modified 2026-09-29.