Ella Core 5G Authentication NAS Message Processing Panic Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Ella Core versions prior to 1.7.0. The issue arises when the software processes Authentication Response and Authentication Failure NAS messages that lack certain Information Elements (IEs). An attacker who sends crafted NAS messages can cause the application to crash, disrupting service for all connected subscribers. This vulnerability does not require authentication to exploit.

Impact

Exploitation of this vulnerability leads to a process crash, causing a service disruption for all connected subscribers.

Reproduction

The vulnerability can be reproduced by sending Authentication Response or Authentication Failure NAS messages that are missing required Information Elements to an instance of Ella Core prior to version 1.7.0. This can be done by crafting NAS messages that intentionally omit specific IEs and transmitting them to the Ella Core application.

Remediation

Users can upgrade to Ella Core version 1.7.0 or later, where this vulnerability has been patched.

Added: Mar 27, 2026, 9:22 PM
Updated: Mar 27, 2026, 9:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.9
remediation
0.0
relevance
4.8
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.