CVE-2026-25658: Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ericsson Packet Core Gateway (PCG)to a version that resolves this vulnerability.Fixed in 1.30
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25658?
CVE-2026-25658 has a severity rating of high, with a score of 7.1 according to the CVSS.
How do I fix CVE-2026-25658?
To fix CVE-2026-25658, you should upgrade to Ericsson Packet Core Gateway (PCG) version 1.30 or later.
What type of vulnerability is CVE-2026-25658?
CVE-2026-25658 is categorized as an Improper Handling of Missing Values vulnerability.
What is the impact of exploiting CVE-2026-25658?
Exploiting CVE-2026-25658 can lead to service degradation that persists as long as the attack continues.
Which software versions are affected by CVE-2026-25658?
CVE-2026-25658 affects all versions of Ericsson Packet Core Gateway (PCG) prior to 1.30.