PatchSiren cyber security CVE debrief
CVE-2026-32963 silex technology, Inc. CVE debrief
CVE-2026-32963 is a cross-site scripting vulnerability in Silex Technology SD-330AC and AMC Manager. According to the CISA CSAF advisory, an attacker could trick a user into visiting a special web page and cause arbitrary script execution in the user’s browser. Vendor-fixed versions are available, and CISA published the initial advisory on 2026-04-21.
- Vendor
- silex technology, Inc.
- Product
- Silex Technology SD-330AC <=1.42 AMC Manager <=5.0.2
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-21
- Original CVE updated
- 2026-04-21
- Advisory published
- 2026-04-21
- Advisory updated
- 2026-04-21
Who should care
Administrators and operators running Silex Technology SD-330AC firmware 1.42 or earlier, or AMC Manager 5.0.2 or earlier, especially where the web management interface is accessible to users.
Technical summary
The advisory describes an Improper Neutralization of Input During Web Page Generation (cross-site scripting) issue affecting Silex Technology SD-330AC and AMC Manager. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network reachability with user interaction required and low confidentiality/integrity impact in the browser context. Remediation is listed for SD-330AC firmware 1.50 or later and AMC Manager 5.1.0 or later; CISA also records a mitigation to disable HTTP/HTTPS service.
Defensive priority
Medium: prioritize near-term remediation because the issue is network-reachable, user interaction is required, and vendor fixes are already available.
Recommended defensive actions
- Upgrade SD-330AC firmware to 1.50 or later.
- Upgrade AMC Manager to 5.1.0 or later.
- If you cannot patch immediately, disable the HTTP/HTTPS service as recommended in the advisory.
- Limit access to the management interface to trusted administrative networks only.
- Review the CISA and JPCERT advisory references for any follow-up guidance or updates.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSA-26-111-10 and its remediation entries, published 2026-04-21. The advisory text states the XSS condition, the affected product/version ranges, the CVSS v3.1 vector, and the vendor-provided fixed versions plus mitigation. The supplied enrichment does not list a KEV entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-32963 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-32963
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-32963 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32963
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-10.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-10
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.