CVE-2026-32319 impacts Ella Core versions prior to 1.5.1, a 5G core designed for private networks, where processing a malformed integrity-protected NGAP/NAS message under 7 bytes causes the system to panic. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated, remote attacker to trigger a denial of service, disrupting service for all connected subscribers. While the impact is significant, there is currently no evidence of active exploitation, public exploit code, or widespread community attention, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.1CPE matchmatch criteria | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.