PT-2026-25087 · Ella Core · Ella Core

P1-Aji

·

Publicado

2026-03-12

·

Atualizado

2026-03-25

·

CVE-2026-32319

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Ella Core versions prior to 1.5.1
Description Ella Core is a 5G core designed for private networks. Prior to version 1.5.1, the software experiences a panic when processing a malformed integrity-protected NGAP/NAS message with a length less than 7 bytes. An attacker capable of sending crafted NAS messages to Ella Core can cause the process to crash, resulting in service disruption for all connected subscribers. No authentication is required for exploitation. The issue involves processing messages via the InitialUEMessage and affects the AMF component. The vulnerability is related to insufficient length verification during NAS message handling.
Recommendations Update Ella Core to version 1.5.1 or later.

Exploit

Correção

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32319
GHSA-M9PM-W3GV-C68F
GO-2026-4692
SUSE-SU-2026:1042-1

Produtos afetados

Ella Core