PatchSiren cyber security CVE debrief
CVE-2015-5621 Raw CVE debrief
CVE-2015-5621 describes an availability issue in net-snmp where SNMP PDU parsing can fail to clean up a varBind entry, allowing a remote attacker to crash the affected service. CISA’s 2026 advisory ties the issue to Silex Technology SD-330AC and AMC Manager deployments and recommends vendor updates or disabling SNMP as a mitigation.
- Vendor
- Raw
- Product
- Silex Technology SD-330AC <=1.42 AMC Manager <=5.0.2
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-21
- Original CVE updated
- 2026-04-21
- Advisory published
- 2026-04-21
- Advisory updated
- 2026-04-21
Who should care
Organizations running Silex Technology SD-330AC firmware or AMC Manager, and any environment exposing SNMP services that rely on affected net-snmp versions, should treat this as an operational availability risk. OT/ICS teams should pay particular attention because the advisory is published in a CISA ICS context and the stated impact is a crash/denial of service.
Technical summary
The supplied advisory states that in net-snmp 5.7.2 and earlier, snmp_pdu_parse in snmp_api.c can leave a varBind variable in a netsnmp_variable_list item uncleared when SNMP PDU parsing fails. The result is a remote denial of service (crash). The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating a network-reachable, low-complexity, availability-only impact. CISA’s source material associates the issue with Silex Technology SD-330AC <=1.42 and AMC Manager <=5.0.2, but the vendor mapping in the provided metadata is marked low confidence and should be validated against the vendor and JPCERT references.
Defensive priority
High for exposed SNMP services, especially in operational environments where a crash could disrupt monitoring, management, or device availability. Priority increases if the affected products are internet-reachable, broadly deployed, or difficult to patch quickly.
Recommended defensive actions
- Upgrade to SD-330AC firmware Ver. 1.50 or later if you operate the affected Silex device.
- Upgrade AMC Manager to Ver. 5.1.0 or later if you use the affected management software.
- Disable the SNMP service where it is not operationally required, as recommended in the advisory.
- Restrict network access to SNMP-capable management interfaces to trusted hosts only.
- Validate whether your environment uses affected net-snmp versions or the Silex products named in the advisory, because the supplied vendor mapping is low confidence.
- Monitor for service crashes or unexpected restarts on exposed SNMP management components until remediation is complete.
Evidence notes
This debrief is based only on the supplied CISA CSAF source item and its listed references. The source text states that snmp_pdu_parse in snmp_api.c in net-snmp 5.7.2 and earlier fails to remove a varBind variable when parsing fails, enabling a remote denial of service (crash). The same source lists vendor remediations of SD-330AC firmware 1.50+ and AMC Manager 5.1.0+, plus the mitigation to disable SNMP service. The supplied metadata marks the vendor mapping as low confidence, so product attribution should be checked against the upstream vendor and JPCERT references before broad rollout.
Sources and references
Verified primary and authoritative sources
-
CVE-2015-5621 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2015-5621
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2015-5621 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2015-5621
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.