PT-2026-26468 · Ella Core · Ella Core
P1-Aji
·
Published
2026-03-19
·
Updated
2026-03-27
·
CVE-2026-33282
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Ella Core versions prior to 1.6.0
Description
Ella Core, a 5G core designed for private networks, experiences a panic when processing a malformed NGAP LocationReport message. Specifically, the issue occurs with the
ue-presence-in-area-of-interest event type when the optional UEPresenceInAreaOfInterestList IE is omitted. An attacker can exploit this by sending crafted NGAP messages to Ella Core, leading to a process crash and service disruption for all connected subscribers. No authentication is required for exploitation. The issue is related to the handling of NGAP messages and the absence of proper IE presence verification.Recommendations
Update to version 1.6.0 or later.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ella Core