Ericsson

First CVE: Apr 4, 2024Active for: 2 years
28
CVEs Published
More CVEs Published than 47% of tracked CNAs
9.3
Avg CVEs / Year
More Avg CVEs / Year than 51% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 67% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Ericsson as a CNA, 85.7% affect products that Ericsson develops as a vendor.

85.7%
14.3%
Self-reported: 24Third-party: 4

Of all the CVEs published that affect products developed by Ericsson, 52.2% are self-published by Ericsson as a CNA.

52.2%
47.8%
Self-published: 24Published by other CNAs: 22

Trends Over Time

The number and severity of CVEs published by Ericsson over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2024
2 years ago
Most Recent CVE
Jun 5, 2026
49 days ago

Top CVEs

All CVEs published by Ericsson as a CNA, regardless of affected vendor or product.

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Auth
Nov 6, 202410.061NOYES
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authenti
Apr 24, 20269.836NONO
Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.
Sep 25, 20259.834NONO
Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
Oct 13, 20259.829NONO
EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Arbitrary Code Execution.
Oct 13, 20258.427NONO
Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended.
Sep 25, 20258.827NONO
Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges.
Sep 25, 20259.827NONO
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degrad
Jun 5, 20266.525NONO
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially
Jun 5, 20266.525NONO
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially
Jun 5, 20266.525NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA28 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (7.1%)
Network17 (60.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network9 (32.1%)
Attack Complexity
Low27 (96.4%)
High1 (3.6%)
Unknown0 (0.0%)
User Interaction
None21 (75.0%)
Unknown0 (0.0%)
Required7 (25.0%)
Privileges Required
Low5 (17.9%)
High2 (7.1%)
None21 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.6% of CVEs· 90th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Ericsson as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Ericsson as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs