CVE-2025-59174: Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker send...
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.
Security readout for executives and security teams
Plain-English summary
Ericsson Packet Core Controller before version 1.39 can suffer service degradation when exposed to a large volume of specially crafted messages. The issue is availability-focused, not data theft or tampering. For telecom environments, degraded packet core control services can become operationally significant.
Executive priority
Treat as a high-priority operational resilience issue for affected telecom packet core environments. Prioritize version confirmation and remediation planning, especially where adjacent network access is broad or hard to govern.
Technical view
CVE-2025-59174 affects Ericsson Packet Core Controller versions prior to 1.39. The CVSS 4.0 vector is AV:A/AC:L/PR:N/UI:N with high vulnerable-system availability impact. The source identifies CWE-228 and describes malformed or specially crafted message volume causing degradation.
Likely exposure
Exposure is limited to organizations running Ericsson Packet Core Controller versions before 1.39, reachable from an adjacent network path. The provided data does not identify other products or public internet exposure.
Exploitation context
The source bundle does not report active exploitation, and KEV is false. The described attack requires high message volume and adjacent-network reachability, with impact limited to service availability degradation.
Researcher notes
Evidence is sparse. The public summary gives product, version threshold, CVSS, CWE, and degradation outcome, but no protocol details, indicators, workaround, or exploit evidence. Avoid assuming broader Ericsson product exposure.
Mitigation direction
Inventory Ericsson Packet Core Controller deployments and confirm exact software versions.
Plan upgrade to PCC version 1.39 or later using Ericsson PSIRT guidance.
Restrict PCC reachability to trusted adjacent network paths only.
Monitor control-plane traffic for abnormal message volume or degradation patterns.
Validation and detection
Check asset records for Ericsson Packet Core Controller instances below version 1.39.
Confirm network paths that can send messages to PCC services.
Review Ericsson PSIRT advisory for environment-specific remediation instructions.
Correlate recent service degradation events with abnormal PCC message volume.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-228: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-228 · source CWE mapping
Improper Handling of Syntactically Invalid Structure
Improper Handling of Syntactically Invalid Structure represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.