CVE-2025-27258 Details
Description
Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
A privilege escalation vulnerability exists in Ericsson Network Manager (ENM) versions prior to 25.1 GA. If exploited, this vulnerability can lead to unauthorized access or elevated privileges within the application.
Users are advised to upgrade to Ericsson Network Manager version 25.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-enm-october-2025 | Ericsson | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | Ericsson |
Affected Products
| Product | Versions |
|---|---|
| ericsson network manager | < 25.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Ericsson |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | Initial Analysis | [email protected] |
| Oct 13, 2025 | New CVE Received | Ericsson |