Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Transport NAS messages without a Request Type. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. Version 1.6.0 adds a guard when receiving an UL NAS Message without a Request Type given no SM Context.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Mar 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks ella Core
|
|
| CPEs | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ellanetworks ella Core
|
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks
Ellanetworks core |
|
| Vendors & Products |
Ellanetworks
Ellanetworks core |
Tue, 24 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Transport NAS messages without a Request Type. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. Version 1.6.0 adds a guard when receiving an UL NAS Message without a Request Type given no SM Context. | |
| Title | Ella Core panics on malformed ULNASTransport Message without a Request Type | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-24T15:12:39.668Z
Reserved: 2026-03-18T18:55:47.425Z
Link: CVE-2026-33283
Updated: 2026-03-24T14:12:40.914Z
Status : Analyzed
Published: 2026-03-24T00:16:30.530
Modified: 2026-03-24T19:30:01.170
Link: CVE-2026-33283
No data.
OpenCVE Enrichment
Updated: 2026-03-25T21:27:50Z