CVE-2025-59174: High severity Ericsson Packet Core Controller (PCC) vulnerability
Published Jun 5, 2026
·Updated
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.
Affected Software
2 affected components
Ericsson Packet Core Controller (PCC)<1.39
Ericsson Packet Core Controller<1.39
Event History
Jun 5, 2026
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59174?
CVE-2025-59174 has a medium severity rating of 6.5.
2
What type of attack is CVE-2025-59174 associated with?
CVE-2025-59174 is associated with an attack that can cause service degradation by sending a large volume of specially crafted messages.
3
How do I mitigate the risk of CVE-2025-59174?
To mitigate CVE-2025-59174, ensure that you are using Ericsson Packet Core Controller (PCC) version 1.39 or later.
4
What impact does CVE-2025-59174 have on the system?
CVE-2025-59174 can result in service degradation due to excessive message handling.
5
Are all versions of Ericsson Packet Core Controller (PCC) vulnerable to CVE-2025-59174?
Yes, all versions prior to 1.39 of Ericsson Packet Core Controller (PCC) are vulnerable to CVE-2025-59174.