CVE-2025-59178

MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability

Title source: cna
STIX 2.1

Description

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

Scores

CVSS v4 4.8
EPSS 0.0015
EPSS Percentile 4.4%
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (1)
Ericsson/Packet Core Controller (PCC) < 1.39
Published Jul 27, 2026
Tracked Since Jul 27, 2026