CVE-2026-32320 identifies a denial-of-service vulnerability in Ella Core, a 5G core for private networks, affecting versions prior to 1.5.1. An unauthenticated attacker can exploit this by sending crafted NGAP messages containing specific zero-length security capability bitstrings, causing the Ella Core process to panic and disrupt service for all connected subscribers. This vulnerability carries a CVSSv3.1 score of 7.5 (HIGH) due to its network-based attack vector and complete availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.1CPE matchmatch criteria | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.