CCCS relays an Ericsson advisory on Packet Core Controller flaws in versions prior to 1.38 and 1.39. If you run PCC, update now; most smaller shops don't operate mobile core gear and can skip this.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — CISO:If you run Ericsson Packet Core Controller, review advisory AV26-743 and bring PCC builds prior to 1.38/1.39 up to the fixed releases.
What this means for you — Lean IT orgs:Most lean-IT shops do not run Ericsson Packet Core Controller. No action unless a carrier or vendor you depend on operates it—ask them if they have patched.
What this means for you — MSP:Inventory telecom and carrier clients for Ericsson PCC; confirm any pre-1.38/1.39 instances are scheduled for the fixed release.
What this means for you — Researcher:Ericsson AV26-743 addresses vulnerabilities in Packet Core Controller prior to 1.38 and 1.39; pull the vendor advisory via the CCCS link for version and fix detail.