CVE-2025-59174: High severity Ericsson Packet Core Controller (PCC) vulnerability
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ericsson Packet Core Controller (PCC)to a version that resolves this vulnerability.Fixed in 1.39
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59174?
CVE-2025-59174 has a medium severity rating of 6.5.
What type of attack is CVE-2025-59174 associated with?
CVE-2025-59174 is associated with an attack that can cause service degradation by sending a large volume of specially crafted messages.
How do I mitigate the risk of CVE-2025-59174?
To mitigate CVE-2025-59174, ensure that you are using Ericsson Packet Core Controller (PCC) version 1.39 or later.
What impact does CVE-2025-59174 have on the system?
CVE-2025-59174 can result in service degradation due to excessive message handling.
Are all versions of Ericsson Packet Core Controller (PCC) vulnerable to CVE-2025-59174?
Yes, all versions prior to 1.39 of Ericsson Packet Core Controller (PCC) are vulnerable to CVE-2025-59174.