PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-32956 silex technology, Inc. CVE debrief

CVE-2026-32956 is a critical heap-based buffer overflow affecting Silex Technology SD-330AC firmware and AMC Manager. According to the CISA CSAF advisory published on 2026-04-21, the issue could allow an attacker to execute arbitrary code on the device. The advisory lists affected versions as SD-330AC firmware 1.42 and earlier, and AMC Manager 5.0.2 and earlier, with vendor fixes available in SD-330AC firmware 1.50 or later and AMC Manager 5.1.0 or later.

Vendor
silex technology, Inc.
Product
Silex Technology SD-330AC <=1.42 AMC Manager <=5.0.2
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-21
Original CVE updated
2026-04-21
Advisory published
2026-04-21
Advisory updated
2026-04-21

Who should care

Asset owners, administrators, and security teams responsible for Silex Technology SD-330AC deployments and AMC Manager environments should treat this as urgent, especially in OT/ICS-adjacent networks where device firmware and management services are exposed.

Technical summary

CISA describes the flaw as a heap-based buffer overflow in Silex Technology SD-330AC and AMC Manager. The supplied CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a network-exploitable issue with no privileges or user interaction required and potential impact to confidentiality, integrity, and availability. The advisory ties remediation to firmware/software updates and also notes a mitigation to disable HTTP/HTTPS service for CVE-2026-32955, CVE-2026-32956, CVE-2026-32957, and CVE-2026-32963.

Defensive priority

Urgent

Recommended defensive actions

  • Upgrade SD-330AC firmware to version 1.50 or later.
  • Upgrade AMC Manager to version 5.1.0 or later.
  • If immediate patching is not possible, disable HTTP/HTTPS service as directed in the advisory.
  • Review exposure of affected devices and restrict management access to trusted administrative networks.
  • Apply CISA ICS recommended practices and monitor for abnormal device behavior after remediation.

Evidence notes

Evidence is drawn from the CISA CSAF advisory ICSA-26-111-10 and its references. The advisory was published on 2026-04-21 and explicitly states: (1) a heap-based buffer overflow exists in Silex Technology SD-330AC and AMC Manager, (2) the vulnerability could allow arbitrary code execution on the device, (3) affected versions are SD-330AC firmware <= 1.42 and AMC Manager <= 5.0.2, and (4) fixes are SD-330AC firmware 1.50+ and AMC Manager 5.1.0+. The supplied data also includes a CVSS 3.1 vector of 9.8/Critical and no KEV listing.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-32956 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-32956

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-32956 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32956

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.