Executive brief
Ericsson Packet Core Controller (PCC), a critical component for managing mobile network traffic, contains a security flaw in its alarm system. The system uses hardcoded login credentials that are the same across installations. An attacker who already has access to the local cluster environment could use these credentials to view sensitive system alerts and alarm data, potentially gaining insights into network health or operational status.
Technical details
A hardcoded credentials vulnerability (CWE-798) exists within the alarm system of Ericsson Packet Core Controller (PCC). The flaw allows an attacker with local access to the cluster to authenticate using static, embedded credentials. Once authenticated, the attacker can gain unauthorized read access to system alarms and alert information. The vulnerability is addressed in PCC version 1.38. The attack vector is classified as local (AV:L) because it requires prior access to the cluster environment.
Affected products
- Ericsson Packet Core Controller (PCC) versions prior to 1.38
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
- 1.38: patched