Executive brief
The Ericsson Packet Core Gateway, a critical component for managing mobile network traffic, is susceptible to a denial-of-service attack. An attacker can send malformed messages to the system to cause service degradation or crashes, potentially disrupting mobile connectivity for users. While the system recovers once the attack stops, the disruption persists as long as the malicious messages are being sent.
Technical details
The vulnerability is classified as Improper Handling of Syntactically Invalid Structure (CWE-228) within the Ericsson Packet Core Gateway (PCG). It is triggered when the system processes specially crafted, syntactically invalid messages, leading to service degradation or software crashes. The attack vector is defined as 'Adjacent,' meaning the attacker must be on the same local network or layer 2 domain as the gateway. No authentication or user interaction is required to exploit this flaw. The impact is a temporary denial of service that persists for the duration of the attack, with the system recovering automatically once the malicious traffic ceases. The issue is resolved in PCG version 1.30.
Affected products
- Ericsson Packet Core Gateway (PCG) prior to 1.30
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory