Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qfxw-v8qx-vj3v | Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponse |
Thu, 28 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks
Ellanetworks core |
|
| Vendors & Products |
Ellanetworks
Ellanetworks core |
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-connection, then creates a GTP tunnel towards that radio. This vulnerability is fixed in 1.10.0. | |
| Title | Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse | |
| Weaknesses | CWE-358 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-28T14:33:35.170Z
Reserved: 2026-05-06T17:18:51.782Z
Link: CVE-2026-44473
Updated: 2026-05-28T14:33:31.342Z
Status : Deferred
Published: 2026-05-27T17:16:39.070
Modified: 2026-06-17T10:50:41.697
Link: CVE-2026-44473
No data.
OpenCVE Enrichment
Updated: 2026-05-28T02:15:03Z
Github GHSA