Processing Flaw in Ella Core 5G Core from Ella Networks
CVE-2026-33903

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33903?

Ella Core, a 5G core solution by Ella Networks, is susceptible to a processing flaw that can be exploited by attackers through specially crafted NGAP Location Report messages. This vulnerability may lead to process crashes, resulting in service disruptions for connected subscribers. The issue primarily affects versions prior to 1.7.0, which introduces necessary safeguards in the NGAP Location Report handler to prevent such attacks. It's crucial for users to update to version 1.7.0 or later to ensure system resilience.

Affected Version(s)

core < 1.7.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.