Executive brief
The Ericsson Packet Core Controller, a critical component in mobile network infrastructure, contains a security flaw in its configuration management system. An attacker with high-level access can discover the identities of other users on the system. This information could be used to facilitate more targeted attacks or unauthorized monitoring of administrative activity.
Technical details
An exposure of sensitive system information vulnerability (CWE-497) exists within the Configuration Management component of Ericsson Packet Core Controller (PCC). The flaw allows an authenticated attacker with high privileges (PR:H) to enumerate other system users. The attack vector is restricted to the adjacent network (AV:A), such as the local management network. This information disclosure can be leveraged for further reconnaissance or targeted credential attacks. The issue is resolved in PCC version 1.39.
Affected products
- Ericsson Packet Core Controller (PCC) versions prior to 1.39
Timeline
- 2026-07-27: advisory: NVD and Ericsson published the vulnerability details.
- 1.39: patched: Vulnerability fixed in version 1.39.