| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m9pm-w3gv-c68f | Ella Core vulnerable to Unauthenticated AMF DoS via malformed InitialUEMessage with undersized integrity-protected NAS payload |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 14 Mar 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks
Ellanetworks core |
|
| Vendors & Products |
Ellanetworks
Ellanetworks core |
Thu, 12 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a malformed integrity protected NGAP/NAS message with a length under 7 bytes. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. This vulnerability is fixed in 1.5.1. | |
| Title | Ella Core: Unauthenticated AMF DoS via malformed InitialUEMessage with undersized integrity-protected NAS payload | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-14T03:45:57.547Z
Reserved: 2026-03-11T21:16:21.661Z
Link: CVE-2026-32319
Updated: 2026-03-14T03:45:53.852Z
Status : Received
Published: 2026-03-13T19:54:42.297
Modified: 2026-03-13T19:54:42.297
Link: CVE-2026-32319
No data.
OpenCVE Enrichment
Updated: 2026-03-13T09:49:33Z
Github GHSA