CVE-2025-59180

MEDIUM

Ericsson Packet Core Controller (PCC) - Use of Hard-Coded Credentials Vulnerability

Title source: rule
STIX 2.1

Description

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

Scores

CVSS v4 5.1
EPSS 0.0011
EPSS Percentile 1.5%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (1)
Ericsson/Packet Core Controller (PCC) < 1.38
Published Jul 27, 2026
Tracked Since Jul 27, 2026