Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
Vulnerability Description
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-connection, then creates a GTP tunnel towards that radio. This vulnerability is fixed in 1.10.0.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Vulnerability Type
不恰当实现的标准安全检查
Vulnerability Title
Ella Core 安全漏洞
Vulnerability Description
Ella Core是Ella Networks开源的一个用于私有网络的5G核心网解决方案。 Ella Core 1.10.0之前版本存在安全漏洞,该漏洞源于未验证PDUSessionResourceSetupResponse消息是否来自与UE逻辑NG连接绑定的SCTP关联,导致具有有效NG设置的无线电可发送伪造消息并创建GTP隧道。
CVSS Information
N/A
Vulnerability Type
N/A