SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2025-59180

MEDIUM · CVSS 5.1 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Ericsson Packet Core Controller (PCC) versions prior to 1.38 are vulnerable due to a hardcoded credential in the alarm system, allowing an attacker with cluster access to read sensitive alarm and alert information. Organizations utilizing affected PCC versions should prioritize remediation to mitigate the risk of unauthorized access to critical operational data.

CVE
CVE-2025-59180
Severity
MEDIUM
CVSS
5.1
EPSS
0.11%

Original NVD Description

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.