PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-32960 silex technology, Inc. CVE debrief

CVE-2026-32960 is a medium-severity flaw in Silex Technology SD-330AC and AMC Manager that CISA says could let an attacker send specially crafted packets and potentially log in to the device. The advisory was published on 2026-04-21 and lists vendor fixes for both affected products.

Vendor
silex technology, Inc.
Product
Silex Technology SD-330AC <=1.42 AMC Manager <=5.0.2
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-21
Original CVE updated
2026-04-21
Advisory published
2026-04-21
Advisory updated
2026-04-21

Who should care

Organizations that use Silex Technology SD-330AC firmware 1.42 or earlier, or AMC Manager 5.0.2 or earlier, should prioritize this advisory—especially teams responsible for device administration, OT/ICS environments, and network access control around these systems.

Technical summary

The CISA CSAF advisory describes a Sensitive Information in Resource Not Removed Before Reuse issue affecting Silex Technology SD-330AC and AMC Manager. The advisory states that specially crafted packets may allow an attacker to log in to the device. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N, with a medium base score of 6.5. Vendor remediations listed in the advisory are SD-330AC firmware 1.50 or later and AMC Manager 5.1.0 or later.

Defensive priority

High for affected deployments: while the score is medium, the impact includes potential device login and the issue is network-reachable with a user-interaction requirement. Patch planning should be prompt for any exposed or operationally sensitive deployments.

Recommended defensive actions

  • Upgrade SD-330AC to firmware version 1.50 or later.
  • Upgrade AMC Manager to version 5.1.0 or later.
  • Review the CISA advisory and the linked Silex Technology/JPCERT notes before scheduling remediation.
  • Apply your normal ICS security and change-management procedures while validating affected device inventory and update coverage.

Evidence notes

This debrief is based on the supplied CISA CSAF record for ICSA-26-111-10, which names CVE-2026-32960, describes the login impact from specially crafted packets, and lists the fixed versions. The supplied metadata also shows CVSS 6.5 (MEDIUM), publishedAt 2026-04-21T06:00:00.000Z, and no CISA KEV listing in the provided enrichment.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-32960 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-32960

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-32960 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32960

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.