What is CVE-2025-59178?
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an exposure of sensitive system information vulnerability in Configuration Management. This allows an authenticated attacker to enumerate other users on the system. Affected PCC nodes should be immediately updated to version 1.39 or later.
Azərbaycanca: Ericsson Packet Core Controller (PCC) 1.39-dan əvvəlki versiyalarda həssas sistem məlumatlarının ifşası zəifliyi aşkar edilib. Bu boşluq Configuration Management modulunda yerləşir və autentifikasiya olunmuş şəxsə sistemdəki digər istifadəçiləri sadalamağa imkan verir. Təsirə məruz qalan PCC qovşaqları dərhal 1.39 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
In which component of Ericsson Packet Core Controller (PCC) does CVE-2025-59178 reside?
The vulnerability lies in the Configuration Management module.
To address this vulnerability, which version should PCC be updated to?
Affected PCC nodes should be immediately updated to version 1.39 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.