Security Flaws in Ella Core 5G Network Solutions by Ella Networks
CVE-2026-44474

3.7LOW

Key Information:

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-44474?

Ella Core, designed for private 5G networks, lacks proper enforcement of security protocols relating to the concurrent execution of security procedures. This oversight allows for the potential issuance of a NAS Security Mode Command despite the existence of a pending N2 handover, or vice versa. Such a sequence can lead to a KgNB mismatch between the User Equipment (UE) and the target gNodeB (gNB), which may ultimately cause handover failures. Resolution for this issue has been implemented in version 1.10.0.

Affected Version(s)

core < 1.10.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.