CVE-2026-25659

CVE-2026-25659

Improper Handling of Missing Values in Ericsson Packet Core Gateway (PCG) Versions Prior to 1.30

Improper Handling of Missing Values in Ericsson Packet Core Gateway (PCG) Versions Prior to 1.30

CVE ID
CVE-2026-25659
CVE Link
https://nvd.nist.gov/vuln/detail/CVE-2026-25659
Vendor
Ericsson
Affected Product & Version
Ericsson Packet Core Gateway (PCG) < 1.30
Vulnerability Type
CWE-230 - Improper Handling of Missing Values
CVSS Base Score / CVSS Vector

NVD: 6.5 Medium  / CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Ericsson: 7.1 High / CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

BDO: 6.5 Medium  / CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Author
Clemens Keil, Manfred Heinz, Patrick Walker
Date
2026-06-05

CVE Details

Description:

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

Remediation:

Update PCG to the most recent version.

References:


Timeline

2025-11-05: Vulnerability discovered

2025-11-05: Vulnerability reported to Ericsson

2026-06-05: CVE published