Ellanetworks maintains Ella Core, a focused networking and infrastructure platform that, despite a narrow product scope, occupies a more prominent position in the vulnerability landscape than its size might suggest. The vendor's exposure centers on memory-safety and privilege-boundary issues—NULL pointer dereferences, out-of-bounds reads, deadlocks, input validation flaws, and improper privilege management—that reflect the low-level systems demands of core networking software. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ellanetworks over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33283HIGH Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Transport NAS messages without a Request Type. An attacker able | Mar 24, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-33282HIGH Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP LocationReport message with `ue-presence-in-area-of-interest` | Mar 24, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-33281HIGH Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with invalid PDU Session IDs outside of 1-15. An attacker able to | Mar 24, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-34761MEDIUM Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP handover failure message. An attacker able to cause a gNodeB t | Apr 2, 2026 | 6.5 | 24 | NO | NO |
CVE-2026-33906HIGH Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore endpoint accepted any v | Mar 27, 2026 | 7.2 | 24 | NO | NO |
CVE-2026-32320HIGH Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchRequest containing UE Security Capabilities with zero-length NR e | Mar 13, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-32319HIGH Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a malformed integrity protected NGAP/NAS message with a length under 7 bytes. | Mar 13, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-33907MEDIUM Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Response and Authentication Failure NAS message missing IEs. An a | Mar 27, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-33904MEDIUM Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire AMF control plane to hang until th | Mar 27, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-33903MEDIUM Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted NGAP LocationReport message. An attacker able to send crafte | Mar 27, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ellanetworks.
Media articles that mention a CVE ID that affects a product developed by Ellanetworks — matched by CVE ID, not by vendor name.