CyberRota Analysis
AI-GeneratedEricsson Packet Core Controller (PCC) versions prior to 1.38 are vulnerable due to a hardcoded credential in the alarm system, allowing an attacker with cluster access to read sensitive alarm and alert information. Organizations utilizing affected PCC versions should prioritize remediation to mitigate the risk of unauthorized access to critical operational data.
CVE
CVE-2025-59180
Severity
MEDIUM
CVSS
5.1
EPSS
0.11%
Original NVD Description
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.