Executive brief
The Ericsson Packet Core Controller, a critical component used in mobile telecommunications networks to manage data traffic, contains a security vulnerability in versions prior to 1.38. An attacker with high-level administrative access could exploit this flaw to take full control of the system with root privileges. This could lead to a complete disruption of mobile services, unauthorized access to network traffic, or a total compromise of the controller's operations.
Technical details
An OS command injection vulnerability (CWE-78) exists in Ericsson Packet Core Controller (PCC) due to improper neutralization of special elements. The flaw allows an authenticated attacker with high privileges (PR:H) to execute arbitrary commands with root-level permissions on the underlying operating system. The attack vector is restricted to the adjacent network (AV:A), typically requiring access to the management network. The vulnerability is resolved in PCC version 1.38.
Affected products
- Ericsson Packet Core Controller (PCC) versions prior to 1.38
Timeline
- 2026-07-27: advisory: NVD and Ericsson published the advisory.
- 1.38: patched: Vulnerability fixed in version 1.38.