Executive brief
The Ericsson Packet Core Gateway, a critical component for managing mobile network traffic, is susceptible to a denial-of-service attack. An attacker can send specifically formatted messages that cause the system to crash or degrade in performance, potentially disrupting mobile data services for users. While the system recovers once the attack stops, the service remains unstable as long as the malicious traffic continues.
Technical details
A vulnerability classified as Improper Handling of Missing Values (CWE-230) exists in Ericsson Packet Core Gateway (PCG) before version 1.30. The flaw is triggered when the gateway processes specially crafted messages missing expected values, leading to system crashes or service degradation. The attack vector is defined as 'Adjacent' (AV:A), meaning the attacker must be on the same local network or subnetwork as the gateway. While the system automatically recovers from crashes once the attack ceases, a persistent attacker can maintain a denial-of-service state. The issue is resolved in PCG version 1.30.
Affected products
- Ericsson Packet Core Gateway (PCG) prior to 1.30
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory