PatchSiren cyber security CVE debrief
CVE-2026-32960 silex technology, Inc. CVE debrief
CVE-2026-32960 is a medium-severity flaw in Silex Technology SD-330AC and AMC Manager that CISA says could let an attacker send specially crafted packets and potentially log in to the device. The advisory was published on 2026-04-21 and lists vendor fixes for both affected products.
- Vendor
- silex technology, Inc.
- Product
- Silex Technology SD-330AC <=1.42 AMC Manager <=5.0.2
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-21
- Original CVE updated
- 2026-04-21
- Advisory published
- 2026-04-21
- Advisory updated
- 2026-04-21
Who should care
Organizations that use Silex Technology SD-330AC firmware 1.42 or earlier, or AMC Manager 5.0.2 or earlier, should prioritize this advisory—especially teams responsible for device administration, OT/ICS environments, and network access control around these systems.
Technical summary
The CISA CSAF advisory describes a Sensitive Information in Resource Not Removed Before Reuse issue affecting Silex Technology SD-330AC and AMC Manager. The advisory states that specially crafted packets may allow an attacker to log in to the device. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N, with a medium base score of 6.5. Vendor remediations listed in the advisory are SD-330AC firmware 1.50 or later and AMC Manager 5.1.0 or later.
Defensive priority
High for affected deployments: while the score is medium, the impact includes potential device login and the issue is network-reachable with a user-interaction requirement. Patch planning should be prompt for any exposed or operationally sensitive deployments.
Recommended defensive actions
- Upgrade SD-330AC to firmware version 1.50 or later.
- Upgrade AMC Manager to version 5.1.0 or later.
- Review the CISA advisory and the linked Silex Technology/JPCERT notes before scheduling remediation.
- Apply your normal ICS security and change-management procedures while validating affected device inventory and update coverage.
Evidence notes
This debrief is based on the supplied CISA CSAF record for ICSA-26-111-10, which names CVE-2026-32960, describes the login impact from specially crafted packets, and lists the fixed versions. The supplied metadata also shows CVSS 6.5 (MEDIUM), publishedAt 2026-04-21T06:00:00.000Z, and no CISA KEV listing in the provided enrichment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-32960 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-32960
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-32960 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32960
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.