CVE-2025-59172: Improper Neutralization of Special Elements used in an OS Command Vulnerability
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ericsson Packet Core Controller (PCC)to a version that resolves this vulnerability.Fixed in 1.38
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59172?
The severity of CVE-2025-59172 is rated at 85, indicating a high risk level.
How do I fix CVE-2025-59172?
To fix CVE-2025-59172, upgrade to Ericsson Packet Core Controller (PCC) version 1.38 or later.
What systems are affected by CVE-2025-59172?
CVE-2025-59172 affects Ericsson Packet Core Controller (PCC) versions prior to 1.38.
What type of vulnerability is CVE-2025-59172?
CVE-2025-59172 is classified as an Improper Neutralization of Special Elements used in an OS Command vulnerability.
What could an attacker achieve by exploiting CVE-2025-59172?
An attacker exploiting CVE-2025-59172 could potentially execute arbitrary code as root on affected systems.