CVE-2026-25659: Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ericsson Packet Core Gateway (PCG)to a version that resolves this vulnerability.Fixed in 1.30
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25659?
The severity of CVE-2026-25659 is rated high with a CVSS score of 7.1.
How do I fix CVE-2026-25659?
To fix CVE-2026-25659, upgrade to Ericsson Packet Core Gateway (PCG) version 1.30 or later.
What type of vulnerability is CVE-2026-25659?
CVE-2026-25659 is classified as an Improper Handling of Missing Values vulnerability.
What is the impact of CVE-2026-25659?
The impact of CVE-2026-25659 includes potential service degradation as a result of an attacker sending specially crafted messages.
Who is affected by CVE-2026-25659?
CVE-2026-25659 affects Ericsson Packet Core Gateway (PCG) versions prior to 1.30.