Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pwfh-mqp3-pqwj | Ella Core has a UE Security Capability bypass on NGAP PathSwitchRequest |
Thu, 28 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellanetworks
Ellanetworks core |
|
| Vendors & Products |
Ellanetworks
Ellanetworks core |
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values. A malicious gNB can overwrite Ella Core's stored UE security capabilities for any UE with arbitrary values by sending a single crafted PathSwitchRequest. This vulnerability is fixed in 1.10.0. | |
| Title | Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest | |
| Weaknesses | CWE-358 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-28T15:36:26.428Z
Reserved: 2026-05-06T17:18:51.782Z
Link: CVE-2026-44475
Updated: 2026-05-28T15:35:58.282Z
Status : Deferred
Published: 2026-05-27T17:16:39.360
Modified: 2026-06-17T10:50:41.893
Link: CVE-2026-44475
No data.
OpenCVE Enrichment
Updated: 2026-05-28T03:30:05Z
Github GHSA