Improper Handling of Syntactically Invalid Structures in Ericsson Packet Core Gateway (PCG) prior to 1.30
Improper Handling of Syntactically Invalid Structures in Ericsson Packet Core Gateway (PCG) prior to 1.30
| CVE ID | CVE-2026-25657 |
| CVE Link | https://nvd.nist.gov/vuln/detail/CVE-2026-25657 |
| Vendor | Ericsson |
| Affected Product & Version | Ericsson Packet Core Gateway (PCG) < 1.30 |
| Vulnerability Type | CWE-228 - Improper Handling of Syntactically Invalid Structure |
| CVSS Base Score / CVSS Vector | NVD: 6.5 Medium / CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Ericsson: 7.1 High / CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N BDO: 6.5 Medium / CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Author | Clemens Keil, Manfred Heinz, Patrick Walker |
| Date | 2026-06-05 |
CVE Details
Description:
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Remediation:
Update PCG to the most recent version.
References:
Timeline
2025-11-05: Vulnerability discovered
2025-11-05: Vulnerability reported to Ericsson
2026-06-05: CVE published

