5G Core Vulnerability in Ella Core by Ella Networks
CVE-2026-33283
6.5MEDIUM
What is CVE-2026-33283?
Ella Core, a 5G core designed for private networks, contains a vulnerability where versions prior to 1.6.0 can panic when confronted with malformed UL NAS Transport messages lacking a Request Type. This flaw enables attackers to send specially crafted messages, causing the process to crash and resulting in service disruption for all connected users. Importantly, no authentication is required to exploit this vulnerability. The introduction of version 1.6.0 mitigates this issue by implementing a safeguard against the reception of UL NAS messages without a Request Type.
Affected Version(s)
core < 1.6.0
