Impact
The vulnerability arises from a deadlock in the AMF's SCTP notification handler within Ella Core, a 5G core designed for private networks. The deadlock causes the AMF control plane to freeze until the process is restarted. An attacker who can reach the N2 interface can trigger this condition, leading to a denial of service that affects all subscribers connected to the network. The weakness is classified as a deadlock condition, identified as CWE‑833.
Affected Systems
Affected vendors and products include Ellanetworks Core, specifically versions prior to 1.7.0. Creators released version 1.7.0 with changes to deferred radio cleanup and removal of stale‑entry scans that address the deadlock. Systems running any older version are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, and no EPSS data is available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires access to the N2 interface, which is typically restricted to administrative or trusted entities. In environments where the N2 interface is exposed or inadequately protected, the risk of denial of service increases, and the need for a timely patch is high.
OpenCVE Enrichment
Github GHSA