---
id: CVE-2025-59178
title: >-
  Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an
  Exposure of Sensitive System Information vulnerability in Configuration
  Management allowing an attacker to enumerate other users on the system.
summary: >-
  Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an
  Exposure of Sensitive System Information vulnerability in Configuration
  Management allowing an attacker to enumerate other users on the system.
severity: none
cwe:
  - CWE-497
published: '2026-07-27'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59178'
references:
  - url: >-
      https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-pcc-july-2026
    label: 85b1779b-6ecd-4f52-bcc5-73eac4659dcf
tags:
  - nvd
epss: 0.00231
epssPercentile: 0.1254
ingestedAt: '2026-09-29T19:44:04.111Z'
---

## Overview

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
