Denial of Service Vulnerability in Ella Core 5G Network Software by Ella Networks
CVE-2026-33904

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33904?

Ella Core, a software solution designed for private 5G networks, suffers from a vulnerability caused by a deadlock in the AMF's SCTP notification handler. This flaw allows an attacker with access to the N2 interface to induce an operational halt of the entire AMF control plane, resulting in a significant denial of service impacting all subscribers. The newly released version 1.7.0 addresses this issue by implementing deferred radio cleanup in the SCTP server, ensuring that every connection exit removes the associated radio. Furthermore, it eliminates the stale-entry scan from SCTP notification handling, enhancing overall network reliability.

Affected Version(s)

core < 1.7.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.