Ella Core NGAP Location Report Processing Vulnerability Leading to Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in Ella Core versions prior to 1.7.0. The issue arises when the application processes specially crafted NGAP LocationReport messages, causing the application to panic and crash. This disruption affects all connected subscribers. An attacker who can send these crafted NGAP messages can exploit this vulnerability to cause a service outage.

Impact

Exploitation of this vulnerability leads to a process crash, causing a service disruption for all connected subscribers.

Reproduction

The vulnerability can be reproduced by sending a crafted NGAP LocationReport message to an instance of Ella Core running a version prior to 1.7.0. This can be done by targeting the application's NGAP message processing functionality, which is part of the 5G core network management.

Remediation

Users can upgrade to Ella Core version 1.7.0 or later, where this vulnerability has been patched.

Added: Mar 27, 2026, 9:25 PM
Updated: Mar 27, 2026, 9:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.9
remediation
0.0
relevance
4.8
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.