Silex Technology SD-330AC and AMC Manager
Silex Technology SD-330AC and AMC Manager have multiple vulnerabilities, including buffer overflows and missing
Run Silex Technology?
Get an email when a reviewed story names Silex Technology, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Multiple vulnerabilities have been discovered in Silex Technology SD-330AC and AMC Manager, including stack and heap-based buffer overflows, missing authentication, and use of hardcoded cryptographic keys. Successful exploitation could lead to arbitrary code execution, denial-of-service, or unauthorized configuration changes. Silex Technology has released updated versions to address these issues.
Full text
ICS Advisory Silex Technology SD-330AC and AMC Manager Release DateApril 21, 2026 Alert CodeICSA-26-111-10 Related topics: Industrial Control System Vulnerabilities, Industrial Control Systems View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, cause a denial-of-service, or configuration information may be altered without authentication. The following versions of Silex Technology SD-330AC and AMC Manager are affected: SD-330AC <=1.42 (CVE-2026-32955, CVE-2026-32956, CVE-2026-32957, CVE-2026-32958, CVE-2015-5621, CVE-2026-32959, CVE-2026-32960, CVE-2026-32961, CVE-2026-32962, CVE-2024-24487, CVE-2026-32963, CVE-2026-32964, CVE-2026-32965) AMC Manager <=5.0.2 (CVE-2026-32955, CVE-2026-32956, CVE-2026-32957, CVE-2026-32958, CVE-2015-5621, CVE-2026-32959, CVE-2026-32960, CVE-2026-32961, CVE-2026-32962, CVE-2024-24487, CVE-2026-32963, CVE-2026-32964, CVE-2026-32965) CVSS Vendor Equipment Vulnerabilities v3 9.8 Silex Technology Silex Technology SD-330AC and AMC Manager Stack-based Buffer Overflow, Heap-based Buffer Overflow, Missing Authentication for Critical Function, Use of Hard-coded Cryptographic Key, Dependency on Vulnerable Third-Party Component, Use of a Broken or Risky Cryptographic Algorithm, Sensitive Information in Resource Not Removed Before Reuse, Incorrect Privilege Assignment, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of CRLF Sequences ('CRLF Injection'), Initialization of a Resource with an Insecure Default Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Japan Vulnerabilities Expand All + CVE-2026-32955 A Stack-based Buffer Overflow vulnerability in Silex Technology SD-330AC and AMC Manager could allow an attacker to execute arbitrary code on the device. View CVE Details Affected Products Silex Technology SD-330AC and AMC Manager Vendor:Silex Technology Product Version:Silex Technology SD-330AC: <=1.42, Silex Technology AMC Manager: <=5.0.2 Product Status:known_affected Remediations Vendor fixThe developer has released the following versions to address this vulnerability: SD-330AC firmware Ver 1.50 or later Vendor fixAMC Manager Ver.5.1.0 or later MitigationCVE-2026-32955, CVE-2026-32956, CVE-2026-32957, and CVE-2026-32963: Disable HTTP/HTTPS service. MitigationFor more information, see Silex Technology's security advisory in English (https://www.silex.jp/support/security-advisories/en/2026-001) or in Japanese (https://www.silex.jp/support/security-advisories/2026-001).https://www.silex.jp/support/security-advisories/en/2026-001 MitigationFor more information, see Silex Technology's security advisory in English (https://www.silex.jp/support/security-advisories/en/2026-001) or in Japanese (https://www.silex.jp/support/security-advisories/2026-001).https://www.silex.jp/support/security-advisories/2026-001 MitigationFor more information, see JPCERT/CC vulnerability notes in English (https://jvn.jp/en/vu/JVNVU94271449/) or in Japanese (https://jvn.jp/vu/JVNVU94271449/).https://jvn.jp/en/vu/JVNVU94271449/ MitigationFor more information, see JPCERT/CC vulnerability notes in English (https://jvn.jp/en/vu/JVNVU94271449/) or in Japanese (https://jvn.jp/vu/JVNVU94271449/).https://jvn.jp/vu/JVNVU94271449/ Relevant CWE: CWE-121 Stack-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2026-32956 A Heap-based Buffer Overflow vulnerability in Silex Technology SD-330AC and AMC Manager could allow an attacker to execute arbitrary code on the device. View CVE Details Affected Products Silex Technology SD-330AC and AMC Manager Vendor:Silex Technology Product Version:Silex Technology SD-330AC: <=1.42, Silex Technology AMC Manager: <=5.0.2 Product Status:known_affected Remediations Vendor fixThe developer has released the following versions to address this vulnerability: SD-330AC firmware Ver 1.50 or later Vendor fixAMC Manager Ver.5.1.0 or later MitigationCVE-2026-32955, CVE-2026-32956, CVE-2026-32957, and CVE-2026-32963: Disable HTTP/HTTPS service. MitigationFor more information, see Silex Technology's security advisory in English (https://www.silex.jp/support/security-advisories/en/2026-001) or in Japanese (https://www.silex.jp/support/security-advisories/2026-001).https://www.silex.jp/support/security-advisories/en/2026-001 MitigationFor more information, see Silex Technology's security advisory in English (https://www.silex.jp/support/security-advisories/en/2026-001) or in Japanese (https://www.silex.jp/support/security-advisories/2026-001).https://www.silex.jp/support/security-advisories/2026-001 MitigationFor more information, see JPCERT/CC vulnerability notes in English (https://jvn.jp/en/vu/JVNVU94271449/) or in Japanese (https://jvn.jp/vu/JVNVU94271449/).https://jvn.jp/en/vu/JVNVU94271449/ MitigationFor more information, see JPCERT/CC vulnerability notes in English (https://jvn.jp/en/vu/JVNVU94271449/) or in Japanese (https://jvn.jp/vu/JVNVU94271449/).https://jvn.jp/vu/JVNVU94271449/ Relevant CWE: CWE-122 Heap-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2026-32957 A Missing Authentication for Critical Function vulnerability in Silex Technology SD-330AC and AMC Manager could allow uploads of arbitrary files to the device without authentication. View CVE Details Affected Products Silex Technology SD-330AC and AMC Manager Vendor:Silex Technology Product Version:Silex Technology SD-330AC: <=1.42, Silex Technology AMC Manager: <=5.0.2 Product Status:known_affected Remediations Vendor fixThe developer has released the following versions to address this vulnerability: SD-330AC firmware Ver 1.50 or later Vendor fixAMC Manager Ver.5.1.0 or later MitigationCVE-2026-32955, CVE-2026-32956, CVE-2026-32957, and CVE-2026-32963: Disable HTTP/HTTPS service. MitigationFor more information, see Silex Technology's security advisory in English (https://www.silex.jp/support/security-advisories/en/2026-001) or in Japanese (https://www.silex.jp/support/security-advisories/2026-001).https://www.silex.jp/support/security-advisories/en/2026-001 MitigationFor more information, see Silex Technology's security advisory in English (https://www.silex.jp/support/security-advisories/en/2026-001) or in Japanese (https://www.silex.jp/support/security-advisories/2026-001).https://www.silex.jp/support/security-advisories/2026-001 MitigationFor more information, see JPCERT/CC vulnerability notes in English (https://jvn.jp/en/vu/JVNVU94271449/) or in Japanese (https://jvn.jp/vu/JVNVU94271449/).https://jvn.jp/en/vu/JVNVU94271449/ MitigationFor more information, see JPCERT/CC vulnerability notes in English (https://jvn.jp/en/vu/JVNVU94271449/) or in Japanese (https://jvn.jp/vu/JVNVU94271449/).https://jvn.jp/vu/JVNVU94271449/ Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2026-32958 A Use of Hard-coded Cryptographic Key vulnerability in Silex Technology SD-330AC and AMC Manager could cause an administrative user to be directed to apply a fake firmware update. View CVE Details Affected Products Silex Technology SD-330AC and AMC Manager Vendor:Silex Technology Product Version:Silex Technology SD-330AC: <=1.42, Silex Technology AMC Manager: <=5.0.2 Product Status:known_affected Remediations Vendor fixThe developer has released the following versions to address this vulnerability: SD-330AC firmware Ver 1.50 or later Vendor fixAMC Manager Ver.5.1.0 or later MitigationCVE-2026-32958 and CVE-2026-32965: Set a password for the settings web interface. MitigationFor more information, see Silex Technology's security advisory in English (https://www.si
Indicators of Compromise
- cve — CVE-2026-32955
- cve — CVE-2026-32956
- cve — CVE-2026-32957
- cve — CVE-2026-32958
- cve — CVE-2015-5621
- cve — CVE-2026-32959
- cve — CVE-2026-32960
- cve — CVE-2026-32961
- cve — CVE-2026-32962
- cve — CVE-2024-24487
- cve — CVE-2026-32963
- cve — CVE-2026-32964
- cve — CVE-2026-32965