By vendor
Ericsson vulnerabilities
Known CVEs affecting Ericsson products, prioritized by severity, with SEC.co remediation and detection guidance.
4 published vulnerabilities
- CVE-2025-59174MEDIUM 6.5
Ericsson's Packet Core Controller (PCC) software versions before 1.39 can be knocked offline or severely degraded when an attacker on the same network segment sends large numbers of specially crafted messages. An attacker doesn't need credentials or user interaction to trigger the problem, but they do need network access to the affected system. This is a denial-of-service vulnerability that could disrupt telecom packet routing and control functions.
- CVE-2026-25657MEDIUM 6.5
Ericsson's Packet Core Gateway (PCG) has a vulnerability that allows an attacker on the local network to send specially crafted messages that crash or degrade the service. The good news: once the attacker stops, the system recovers automatically without manual intervention. This is a denial-of-service issue—it takes the service offline temporarily but doesn't steal data or give attackers permanent control. Organizations running PCG versions before 1.30 are at risk.
- CVE-2026-25658MEDIUM 6.5
Ericsson Packet Core Gateway versions before 1.30 contain a vulnerability where attackers can send specially crafted messages to degrade service availability. The system crashes repeatedly while the attack continues, but recovers automatically once the attacker stops. This is a network-based attack requiring no authentication or user interaction.
- CVE-2026-25659MEDIUM 6.5
Ericsson's Packet Core Gateway (PCG) has a vulnerability that allows attackers on the local network to degrade service by repeatedly sending specially crafted messages. The system becomes unresponsive while attacks continue, but recovers normally once the attacker stops. This is not a persistent damage vulnerability—it's a denial-of-service condition that requires active, ongoing attack traffic.