CVE-2026-32320Disclosure(ellanetworks / ella_core)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchRequest containing UE Security Capabilities with zero-length NR encryption or integrity protection algorithm bitstrings, resulting in a denial of service. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. No authentication is required. This vulnerability is fixed in 1.5.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ella_core

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-13)
  • 3 total mentions across 2 days

Affected systems

Products
ella_core

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-12: 1Mentions · 2026-03-13: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 203-1203-13
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-132
Disclosure1General1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 Ella Core, Out-of-bounds Read, #CVE-2026-32320 (Moderate) https://dailycve.com/ella-core-out-of-bounds-read-cve-2026-32320-moderate/

    Post summary

    The tweet announces CVE-2026-32320, an out-of-bounds read vulnerability in Ella Core, classified as moderate severity.

    0000029
    168 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-32320 - Ella Core: AMF DoS via malformed PathSwitchRequest with empty NR security capability bitstrings Intel Report: https://ift.tt/KH8mVCg

    Post summary

    The alert identifies CVE-2026-32320, a DoS flaw in Ella Core’s AMF triggered by malformed PathSwitchRequest messages, and links to an Intel report, but it offers no PoC, exploit, patch, or evidence of active exploitation.

    0000036
    340 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32320 Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchRequest containing UE Security Capabilities with ze… https://www.cve.org/CVERecord?id=CVE-2026-32320

    Post summary

    CVE-2026-32320 is a fatal panic in Ella Core 5G before v1.5.1 when processing certain PathSwitchRequests; no exploit, active use, or mitigation details are provided.

    0000071
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appellanetworksella_core---

Explore more