Executive brief
Ericsson Packet Core Controller, a critical component in mobile network infrastructure, contains a security flaw in its configuration management system. An attacker with high-level administrative access could use specially crafted commands to force the system to reveal sensitive internal secrets through error messages. This could lead to the exposure of credentials or other confidential system data, potentially compromising the security of the mobile core network.
Technical details
A sensitive information disclosure vulnerability (CWE-209) exists in the Configuration Management component of Ericsson Packet Core Controller (PCC). The flaw allows an authenticated attacker with high privileges (PR:H) to execute crafted commands that trigger error messages containing system secrets. The attack vector is restricted to the adjacent network (AV:A). This vulnerability could be used to extract sensitive configuration data or credentials. The issue is resolved in Ericsson PCC version 1.39.
Affected products
- Ericsson Packet Core Controller (PCC) versions prior to 1.39
Timeline
- 2026-07-27: advisory: NVD publication date
- 2026-07-27: disclosed: Initial disclosure by Ericsson