LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-33281

ellanetworks · ella core

Published
CVSS6.5
Severitymedium
WeaknessCWE-129
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Description

Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with invalid PDU Session IDs outside of 1-15. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. Version 1.6.0 added PDU Session ID validations during NGAP message handling.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33281

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33281.