Impact
Ella Core is a 5G core designed for private networks. A flaw causes the core to crash when it receives malformed UL NAS Transport messages that do not include a Request Type. The crash terminates critical processing, leaving all connected subscribers without service and creating a denial of service. The weakness is a classic null pointer dereference mapped to CWE‑476, and no authentication is needed to trigger it.
Affected Systems
All deployments of Ellanetworks:core running a pre‑1.6.0 release are affected. The CPE identifier for Ella Core identifies these releases. From version 1.6.0 onward a guard was added that prevents the crash even when a UL NAS message lacks a Request Type.
Risk and Exploitability
The vulnerability carries a moderate severity rating of 6.5. An estimated exploitation likelihood is below 1%, and it is not listed in the CISA Known Exploited Vulnerabilities catalogue. An attacker can reach the vulnerable component by sending crafted NAS messages over the network, which does not require privilege or authentication. While the probability of exploitation is low, any successful exploitation would result in a complete outage of the 5G core and could seriously disrupt services that depend on it.
OpenCVE Enrichment
Github GHSA