CVE-2026-34762
- EPSS 0.08%
- Veröffentlicht 02.04.2026 19:03:54
- Zuletzt bearbeitet 07.04.2026 16:51:09
Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API accepts an IMSI identifier from both the URL path and the JSON request body but never verifies they match. This allows an authenticate...
CVE-2026-34761
- EPSS 0.06%
- Veröffentlicht 02.04.2026 19:03:05
- Zuletzt bearbeitet 07.04.2026 16:51:35
Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP handover failure message. An attacker able to cause a gNodeB to send NGAP handover failure messages to Ella Core can crash the proce...
CVE-2026-33907
- EPSS 0.03%
- Veröffentlicht 27.03.2026 20:58:06
- Zuletzt bearbeitet 20.04.2026 12:32:36
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Response and Authentication Failure NAS message missing IEs. An attacker able to send crafted NAS messages to Ella Core can crash the p...
CVE-2026-33906
- EPSS 0.04%
- Veröffentlicht 27.03.2026 20:56:35
- Zuletzt bearbeitet 20.04.2026 12:33:13
Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents. A NetworkManager coul...
CVE-2026-33904
- EPSS 0.02%
- Veröffentlicht 27.03.2026 20:55:18
- Zuletzt bearbeitet 20.04.2026 12:32:55
Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire AMF control plane to hang until the process is restarted. An attacker with access to the N2 interface ca...
CVE-2026-33903
- EPSS 0.02%
- Veröffentlicht 27.03.2026 20:52:37
- Zuletzt bearbeitet 20.04.2026 12:29:28
Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted NGAP LocationReport message. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service di...
CVE-2026-33283
- EPSS 0.02%
- Veröffentlicht 23.03.2026 23:49:42
- Zuletzt bearbeitet 24.03.2026 19:30:01
Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Transport NAS messages without a Request Type. An attacker able to send crafted NAS messages to Ella Core can crash the process, caus...
CVE-2026-33282
- EPSS 0.02%
- Veröffentlicht 23.03.2026 23:47:26
- Zuletzt bearbeitet 24.03.2026 19:31:44
Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP LocationReport message with `ue-presence-in-area-of-interest` event type and omitting the optional `UEPresenceInAreaOfInterestList` ...
CVE-2026-33281
- EPSS 0.02%
- Veröffentlicht 23.03.2026 23:46:12
- Zuletzt bearbeitet 24.03.2026 19:36:10
Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with invalid PDU Session IDs outside of 1-15. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing...
CVE-2026-32320
- EPSS 0.05%
- Veröffentlicht 12.03.2026 21:34:50
- Zuletzt bearbeitet 19.03.2026 13:38:45
Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchRequest containing UE Security Capabilities with zero-length NR encryption or integrity protection algorithm bitstrings, resulting in a...