Executive brief
Ericsson Packet Core Controller (PCC), a critical component in mobile telecommunications networks, is affected by a security flaw in its configuration management system. An attacker with high-level administrative access could exploit this to modify folder permissions on the system. This could lead to a denial of service by preventing legitimate users or system processes from accessing necessary files, potentially disrupting mobile network operations.
Technical details
A path traversal vulnerability (CWE-35) exists in the Configuration Management component of Ericsson Packet Core Controller (PCC) versions prior to 1.39. The flaw allows an authenticated attacker with high privileges (PR:H) to traverse the file system via adjacent network access (AV:A). By exploiting this, the attacker can modify directory permissions, which can result in a partial loss of integrity and availability by locking out legitimate users or system services. The issue is resolved in PCC version 1.39.
Affected products
- Ericsson Packet Core Controller (PCC) versions prior to 1.39
Timeline
- 2026-07-27: advisory: Initial disclosure by Ericsson and NVD publication.
- 1.39: patched: Vulnerability fixed in version 1.39.