CVE-2025-59178
MEDIUM
4.8
CVSS 4.0
Description
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
Metadata
Severity & Metrics
4.8
MEDIUM CVSS 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Ericsson | Packet Core Controller (PCC) | — | 0 < 1.39 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-497 | cna | CWE-497 Exposure of sensitive system information to an unauthorized control sphere |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 4.8 | MEDIUM | 4.0 | cna | CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |