CVE-2026-33282 PUBLISHED CVSS 7.5 HIGH

Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP LocationReport message with `ue-presence-in-area-of-interest` event type and omitting the optional `UEPresenceInAreaOfInterestList` IE. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. Version 1.6.0 added IE presence verification to NGAP message handling.

EPSS 0.02% · 4.8th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.02%
4.8th percentile

Affected Products

VendorProductVersions
ellanetworksella_core0, 0, 0
ellanetworkscore< 1.6.0, < 1.6.0, < 1.6.0
github.comellanetworks/core0, 0, 0

Timeline

References

Open in Interactive Console →