PT-2026-25087 · Ella Core · Ella Core
P1-Aji
·
Publicado
2026-03-12
·
Atualizado
2026-03-25
·
CVE-2026-32319
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Ella Core versions prior to 1.5.1
Description
Ella Core is a 5G core designed for private networks. Prior to version 1.5.1, the software experiences a panic when processing a malformed integrity-protected NGAP/NAS message with a length less than 7 bytes. An attacker capable of sending crafted NAS messages to Ella Core can cause the process to crash, resulting in service disruption for all connected subscribers. No authentication is required for exploitation. The issue involves processing messages via the
InitialUEMessage and affects the AMF component. The vulnerability is related to insufficient length verification during NAS message handling.Recommendations
Update Ella Core to version 1.5.1 or later.
Exploit
Correção
DoS
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ella Core