CISA has issued an industrial control systems advisory for a vulnerability affecting the Baicells Nova 430H eNodeB. The agency says an unauthenticated device within radio range can send a malformed uplink message during connection setup and trigger temporary loss of signaling for the affected cell.
Invalid signaling can affect availability
The issue is tracked as CVE-2026-96274 and affects the Nova 430H model pBS3101SH at the versions identified by CISA. According to the advisory, the eNodeB does not adequately validate an invalid NAS payload before forwarding it to the core network. The resulting condition can shut down the signaling association until connectivity is re-established. CISA rates the issue High and says no public exploitation specifically targeting it has been reported.
Reduce exposure and plan around service risk
CISA states that no fix was planned at publication time and advises affected users to contact the vendor. Operators should inventory deployed versions, restrict management exposure, monitor signaling interruptions and evaluate compensating controls with the network provider. Because exploitation requires radio proximity rather than ordinary remote internet access, physical coverage and access around sites also belong in the risk review. SectechMedia’s guide to network redundancy for IP security systems explains why recovery paths and tested failover are important when communications infrastructure can be disrupted.

Leave a Reply