Vulnerabilities in Ericsson
37 resultsVexday analysis
Ericsson apresenta 29 vulnerabilidades catalogadas, com 2 classificadas como críticas e 5 publicadas nos últimos 90 dias, indicando exposição contínua. A fraqueza dominante é validação inadequada de entrada (CWE-20), típica de produtos complexos. Nenhuma vulnerabilidade está sob ataque ativo no momento, reduzindo a urgência imediata, mas o volume e recência das divulgações justificam monitoramento ativo.
CVE-2024-25011MEDIUMEricsson Catalog Manager and Ericsson Order Care - Exposure of Sensitive Information VulnerabilityEPSS 0.3%CVE-2026-25659HIGHEricsson Packet Core Gateway (PCG) - Improper handling of missing values VulnerabilityEPSS 0.3%CVE-2026-25658HIGHEricsson Packet Core Gateway (PCG) - Improper handling of missing values VulnerabilityEPSS 0.3%CVE-2026-25657HIGHEricsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure VulnerabilityEPSS 0.3%CVE-2024-25009MEDIUMEricsson Packet Core Controller (PCC) - Improper Input Validation VulnerabilityEPSS 0.3%CVE-2025-1300MEDIUMOpen redirect in CodeChecker web serverEPSS 0.3%CVE-2024-53829HIGHCross-Site Request Forgery in CodeChecker APIEPSS 0.3%CVE-2025-59177MEDIUMGeneration of Error Message Containing Sensitive Information VulnerabilityEPSS 0.2%CVE-2025-59178MEDIUMExposure of Sensitive System Information to an Unauthorized Control Sphere VulnerabilityEPSS 0.2%CVE-2025-27260HIGHEricsson Indoor Connect 8855 - Improper Filtering of Special Elements VulnerabilityEPSS 0.2%CVE-2025-27259LOWEricsson Network Manager: improper neutralization of user controlled inputEPSS 0.2%CVE-2025-40843MEDIUMBuffer overflow in CodeChecker log commandEPSS 0.2%CVE-2026-58106LOWIncomplete fix for CVE-2025-40843: safe_strcpy is called with PATH_MAX into fullPath+2, writing 2 bytes past the buffer on every CodeChecker log invocationEPSS 0.2%CVE-2025-59174HIGHEricsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially cEPSS 0.2%CVE-2025-59180MEDIUMUse of Hard-coded Credentials VulnerabilityEPSS 0.2%CVE-2025-40842HIGHEricsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation VulnerabilityEPSS 0.1%CVE-2025-40841MEDIUMEricsson Indoor Connect 8855 - Cross-Site Request Forgery VulnerabilityEPSS 0.1%