| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-826q-wrq4-p23x | Ella Core panics on malformed NGAP Location Report |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 25 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks ella Core
|
|
| CPEs | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ellanetworks ella Core
|
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks
Ellanetworks core |
|
| Vendors & Products |
Ellanetworks
Ellanetworks core |
Tue, 24 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP LocationReport message with `ue-presence-in-area-of-interest` event type and omitting the optional `UEPresenceInAreaOfInterestList` IE. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. Version 1.6.0 added IE presence verification to NGAP message handling. | |
| Title | Ella Core panics on malformed NGAP Location Report | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T19:25:14.461Z
Reserved: 2026-03-18T18:55:47.425Z
Link: CVE-2026-33282
Updated: 2026-03-25T19:25:00.612Z
Status : Analyzed
Published: 2026-03-24T00:16:30.370
Modified: 2026-03-24T19:31:44.117
Link: CVE-2026-33282
No data.
OpenCVE Enrichment
Updated: 2026-03-25T21:27:51Z
Github GHSA