PT-2026-26467 · Go · Github.Com/Ellanetworks/Core
Published
2026-03-19
·
Updated
2026-03-19
·
CVE-2026-33281
CVSS v3.1
6.5
Medium
| AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Summary
Ella Core panics when processing NGAP messages with invalid PDU Session IDs outside of 1-15.
Impact
An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required.
Fix
Added PDU Session ID validations during NGAP message handling.
Fix
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github.Com/Ellanetworks/Core