Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Transport NAS messages without a Request Type. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. Version 1.6.0 adds a guard when receiving an UL NAS Message without a Request Type given no SM Context.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3366-gw57-fcm5 | Ella Core panics on malformed ULNASTransport Message without a Request Type |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 24 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks ella Core
|
|
| CPEs | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ellanetworks ella Core
|
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks
Ellanetworks core |
|
| Vendors & Products |
Ellanetworks
Ellanetworks core |
Tue, 24 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Transport NAS messages without a Request Type. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. Version 1.6.0 adds a guard when receiving an UL NAS Message without a Request Type given no SM Context. | |
| Title | Ella Core panics on malformed ULNASTransport Message without a Request Type | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-24T15:12:39.668Z
Reserved: 2026-03-18T18:55:47.425Z
Link: CVE-2026-33283
No data.
Status : Analyzed
Published: 2026-03-24T00:16:30.530
Modified: 2026-03-24T19:30:01.170
Link: CVE-2026-33283
No data.
OpenCVE Enrichment
Updated: 2026-03-24T10:29:43Z
Weaknesses
Github GHSA