Junglewise Threat Intelligence

CVE-2025-59174: Ericsson Packet Core Controller denial of service via malformed messages

CVE-2025-59174 · Severity: medium · CVSS 6.5 · Published 2026-06-05

Technologies: Ericsson Packet Core Controller. Vendors: Ericsson.

Executive brief

The Ericsson Packet Core Controller, a critical component in mobile telecommunications networks for managing data traffic, is vulnerable to a denial-of-service attack. An attacker on the same local network can send a high volume of malformed messages to the system, causing it to slow down or become unavailable. This could lead to service disruptions for mobile users and impact the overall reliability of the cellular network infrastructure.

Technical details

The Ericsson Packet Core Controller (PCC) is susceptible to a denial-of-service (DoS) vulnerability due to improper handling of syntactically invalid structures (CWE-228). An unauthenticated attacker with adjacent network access can exploit this by flooding the controller with a large volume of specially crafted messages. This resource exhaustion or processing error leads to significant service degradation or loss of availability. The vulnerability is addressed in PCC version 1.39. The CVSS 4.0 score provided by the vendor is 7.1, while the CVSS 3.1 score is 6.5.

Affected products

  • Ericsson Packet Core Controller (PCC) prior to 1.39

Timeline

  • 2026-06-05: advisory: NVD and Ericsson published the vulnerability details.
  • 2026-06-05: patched: Fix available in version 1.39.

References

Related threats