CVE-2025-59180
Severity CVSS v4.0:
MEDIUM
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
27/07/2026
Last modified:
27/07/2026
Description
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM



