Full Report
Ericsson security advisory (AV26-743)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Ericsson Packet Core Controller (PCC)
## CVE Details
- **CVE ID:** [Pending/Not specified in advisory summary]*
- **CVSS Score:** [See Note]*
- **CWE:** [Not specified]*
*\*Note: The provided source (AV26-743) indicates a formal security advisory release by Ericsson; however, specific CVE identifiers and CVSS breakdown are typically found within the restricted Ericsson Support portal linked in the full bulletin.*
## Affected Systems
- **Products:** Ericsson Packet Core Controller (PCC)
- **Versions:**
- Versions prior to 1.38
- Versions prior to 1.39
- **Configurations:** Systems running affected software revisions within mobile core network environments.
## Vulnerability Description
While the specific technical root cause (e.g., buffer overflow, injection, or logic error) is contained within the detailed vendor advisory, these vulnerabilities affect the **Packet Core Controller (PCC)**. The PCC is a critical infrastructure component used for policy control and charging rules; vulnerabilities in this layer typically involve risks to session management or signaling plane stability.
## Exploitation
- **Status:** Not explicitly reported as exploited in the wild at the time of publication.
- **Complexity:** [Varies based on specific CVE]
- **Attack Vector:** Typically Network/Adjacent (Protocol-based)
## Impact
- **Confidentiality:** Potential for sensitive subscriber information disclosure.
- **Integrity:** Potential for unauthorized modification of policy or charging rules.
- **Availability:** Potential for Denial of Service (DoS) affecting mobile core services.
## Remediation
### Patches
Ericsson has released fixed versions to address these flaws. Administrators are advised to upgrade to:
- **Packet Core Controller (PCC) version 1.38** (or later)
- **Packet Core Controller (PCC) version 1.39** (or later)
### Workarounds
- No specific workarounds have been publicly disclosed. Patching to the supported versions is the primary recommendation.
## Detection
- **Indicators of compromise:** Monitor PCC logs for unusual signaling patterns or unauthorized administrative access attempts.
- **Detection methods and tools:** Use vendor-specific diagnostic tools to verify software checksums and versioning.
## References
- **Vendor Advisory:** Restricted access via Ericsson Extranet/Support Portal.
- **Canadian Centre for Cyber Security (CCCS) Advisory:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/ericsson-security-advisory-av26-743
- **Government of Canada Bulletin:** hxxps[://]www[.]canada[.]ca/en[.]html