CVE-2025-59178: Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability
Published Jul 27, 2026
·Updated
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
Affected Software
1 affected component
Ericsson Packet Core Controller (PCC)<1.39
Event History
Jul 27, 2026
CVE Published
via MITRE·02:15 PM
Data Sourced
via MITRE·02:15 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-59178?
CVE-2025-59178 has a risk rating of 23, indicating a significant level of vulnerability.
2
How do I fix CVE-2025-59178?
To fix CVE-2025-59178, upgrade to Ericsson Packet Core Controller (PCC) version 1.39 or later.
3
What types of information can be exposed due to CVE-2025-59178?
CVE-2025-59178 allows attackers to potentially enumerate sensitive system information, including other users on the system.
4
Which versions of Ericsson Packet Core Controller are affected by CVE-2025-59178?
CVE-2025-59178 affects all versions of Ericsson Packet Core Controller (PCC) prior to 1.39.
5
What is the impact of CVE-2025-59178 on system security?
CVE-2025-59178 can lead to unauthorized access and enumeration of users, compromising the confidentiality of the system.