Skip to main content

Improperly Implemented Security Check for Standard

CVE-2026-44473

Severity Low
Score 0/10

Summary

A radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-connection, then creates a GTP tunnel towards that radio. This issue affects versions prior to 1.10.0.

  • LOW
  • ADJACENT
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • HIGH

CWE-358 - Improperly Implemented Security Check for Standard

The software does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

References

Advisory Timeline

  • Published