CVE-2025-59172
Ericsson · Packet Core Controller (PCC)
Ericsson Packet Core Controller (PCC) is vulnerable to OS command injection due to improper neutralization of special elements, allowing an authenticated user to execute arbitrary commands.
Executive summary
An OS command injection vulnerability in the Ericsson Packet Core Controller allows an authenticated attacker to execute arbitrary commands with elevated system privileges.
Vulnerability
This vulnerability is a classic OS command injection (CWE-78) flaw. It requires an attacker to possess high privileges (PR:H) to successfully interact with the vulnerable function, making this an authenticated vulnerability.
Business impact
Successful exploitation allows an attacker to execute arbitrary commands on the controller, which can lead to a complete system compromise. Given the CVSS score of 8.5, the risk to confidentiality, integrity, and availability is high, as the controller is a critical component for network infrastructure.
Remediation
Immediate Action: Update the Ericsson Packet Core Controller to version 1.38 or later as specified in the official vendor security bulletin.
Proactive Monitoring: Monitor system logs for unusual command execution patterns or unauthorized shell activity originating from administrative accounts.
Compensating Controls: Ensure strict access control lists are in place to limit management interface access only to authorized administrative workstations.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Organizations utilizing Ericsson Packet Core Controller must prioritize this update, as command injection flaws in core network infrastructure represent a critical security risk. Apply the vendor-provided patch immediately to prevent unauthorized control of the network environment.