Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q669-4gmv-g8mf | Ella Core panics on invalid PDU Session IDs in NGAP messages |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 24 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks
Ellanetworks core |
|
| Vendors & Products |
Ellanetworks
Ellanetworks core |
Tue, 24 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with invalid PDU Session IDs outside of 1-15. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. Version 1.6.0 added PDU Session ID validations during NGAP message handling. | |
| Title | Ella Core panics on invalid PDU Session IDs in NGAP messages | |
| Weaknesses | CWE-129 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-24T13:32:41.782Z
Reserved: 2026-03-18T18:55:47.425Z
Link: CVE-2026-33281
Updated: 2026-03-24T13:32:17.648Z
Status : Received
Published: 2026-03-24T00:16:30.200
Modified: 2026-03-24T00:16:30.200
Link: CVE-2026-33281
No data.
OpenCVE Enrichment
Updated: 2026-03-24T10:29:45Z
Github GHSA