CVE-2026-33282
7.5Ella Networks · Core
A NULL pointer dereference in Ella Core allows unauthenticated attackers to cause a process crash and service disruption via crafted NGAP messages.
Executive summary
A critical vulnerability in Ella Core allows unauthenticated remote attackers to trigger a denial of service condition by sending malformed NGAP messages.
Vulnerability
The software fails to properly handle malformed NGAP LocationReport messages that omit the optional UEPresenceInAreaOfInterestList information element, resulting in a NULL pointer dereference. This vulnerability is exploitable by an unauthenticated attacker capable of sending crafted NGAP messages to the core network.
Business impact
Successful exploitation results in a complete crash of the Ella Core process, leading to a total loss of connectivity for all subscribers connected to the private network. Given the critical role of the 5G core in network operations, this denial of service vulnerability poses a significant risk to business continuity and operational availability. With a CVSS score of 7.5, the impact on service availability is high, necessitating immediate attention.
Remediation
Immediate Action: Upgrade Ella Core to version 1.6.0 or later, which introduces necessary input validation for NGAP message handling.
Proactive Monitoring: Monitor network infrastructure logs for an unusual volume of rejected or malformed NGAP messages that may indicate an attempt to trigger this crash.
Compensating Controls: Implement strict network access controls to limit the sources capable of sending NGAP traffic to the Core, effectively restricting the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a significant threat to the availability of private 5G networks. Administrators should prioritize the deployment of version 1.6.0 to eliminate the underlying logic flaw. Until patching is complete, ensure that infrastructure access is restricted to authorized network components to prevent external actors from reaching the vulnerable interface.