製品・ソフトウェアに関する情報
サイレックス・テクノロジー製SD-330ACおよびAMC Managerにおける複数の脆弱性
Title サイレックス・テクノロジー製SD-330ACおよびAMC Managerにおける複数の脆弱性
Summary

サイレックス・テクノロジー株式会社が提供するSD-330ACおよびAMC Managerには、次の複数の脆弱性が存在します。<a href='https://cwe.mitre.org/data/definitions/121.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/122.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/306.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/321.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/327.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/226.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/122.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/306.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/79.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/93.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/1188.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/1395.html' target='_blank'></a><a href='https://cwe.mitre.org/data/definitions/266.html' target='_blank'></a><ul><li>リダイレクトURLの処理におけるスタックベースのバッファオーバーフロー(CWE-121) - CVE-2026-32955</li><li>リダイレクトURLの処理におけるヒープベースのバッファオーバーフロー(CWE-122) - CVE-2026-32956</li><li>ファームウェアに関する重要な機能に対する認証の欠如(CWE-306) - CVE-2026-32957</li><li>ハードコードされた暗号鍵の使用(CWE-321) - CVE-2026-32958</li><li>解読される恐れの高い暗号アルゴリズムの使用(CWE-327) - CVE-2026-32959</li><li>リソース内の機微な情報がリソースの再利用前に削除されない(CWE-226) - CVE-2026-32960</li><li>sx_smpdのパケットデータ処理におけるヒープベースのバッファオーバーフロー(CWE-122) - CVE-2026-32961</li><li>デバイス設定に関する重要な機能に対する認証の欠如(CWE-306) - CVE-2026-32962</li><li>反射型クロスサイトスクリプティング(CWE-79) - CVE-2026-32963</li><li>CRLFインジェクション(CWE-93) - CVE-2026-32964</li><li>安全ではない値を用いたリソースの初期化(CWE-1188) - CVE-2026-32965</li><li>脆弱なサードパーティ製コンポーネントの使用(CWE-1395) - CVE-2015-5621</li><li>不適切な権限の割り当て(CWE-266) - CVE-2024-24487</li></ul>この脆弱性情報は、下記の方がCISA ICSに報告し、CISA ICSから依頼を受けたJPCERT/CCが開発者との調整を行いました。 報告者:Forescout Technologies Francesco La Spina 氏

Possible impacts 想定される影響は各脆弱性により異なりますが、次のような影響を受ける可能性があります。<ul><li>当該機器上で任意のコードが実行される(CVE-2026-32955、CVE-2026-32956)</li><li>認証なしに当該機器上に任意のファイルがアップロードされる(CVE-2026-32957)</li><li>偽のファームウェアアップデートを適用させられる(CVE-2026-32958)</li><li>AMC Managerとデバイスとの間の通信に対して中間者攻撃が行われた場合、設定データなどを取得される(CVE-2026-32959)</li><li>細工されたパケットにより、パスワードなしでログインされる(CVE-2026-32960)</li><li>細工されたパケットを処理することで、一時的にサービス運用妨害(DoS)状態にされる(CVE-2026-32961)</li><li>認証なしに設定を改ざんされる(CVE-2026-32962)</li><li>当該機器にログインしているユーザが細工されたページにアクセスすると、ユーザのブラウザ上で意図しない処理が実行される(CVE-2026-32963)</li><li>細工された設定データを処理すると、システム設定に任意のエントリを追加される(CVE-2026-32964)</li><li>パスワードを設定しないままネットワークに接続している場合、長さ0の文字列をパスワードとして当該機器の設定を変更される(CVE-2026-32965)</li><li>当該機器に組み込まれているnet-snmpの古い脆弱なバージョンのプログラムに対する攻撃を意図したパケットを処理することにより、サービス運用妨害(DoS)状態にされる(CVE-2015-5621)</li><li>認証なしに当該機器を再起動される(CVE-2024-24487)</li></ul>
Solution

[アップデートする] 開発者が提供する情報をもとに、最新版へアップデートしてください。 本脆弱性は、次のバージョンで修正されています。 <ul> <li>SD-330AC ファームウェア Ver.1.50以降</li> <li>AMC Manager Ver.5.1.0以降</li> </ul> [ワークアラウンドを実施する] <b>CVE-2026-32955、CVE-2026-32956、CVE-2026-32957、CVE-2026-32963</b> HTTP/HTTPSサービスを無効化してください。 <b>CVE-2026-32958、CVE-2026-32965</b> 設定WEBにパスワードを設定する。 <b>CVE-2015-5621</b> SNMPサービスを無効化してください。

Publication Date April 20, 2026, midnight
Registration Date April 21, 2026, 12:35 p.m.
Last Update April 23, 2026, 5:36 p.m.
CVSS3.0 : 重要
Score 8.8
Vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected System
サイレックス・テクノロジー株式会社
AMC Manager Ver.5.0.2およびそれ以前のバージョン
SD-330AC Ver.1.42およびそれ以前のバージョン
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
No Changed Details Date of change
2 [2026年04月23日]
  参考情報:ICS-CERT ADVISORY (ICSA-26-111-10) を追加
April 23, 2026, 5:25 p.m.
1 [2026年04月21日]   掲載 April 21, 2026, 7:02 a.m.

NVD Vulnerability Information
CVE-2015-5621
Summary

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

Publication Date Aug. 20, 2015, 12:59 a.m.
Registration Date Jan. 26, 2021, 2:53 p.m.
Last Update Nov. 21, 2024, 11:33 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:net-snmp:net-snmp:*:*:*:*:*:*:*:* 5.7.2
Related information, measures and tools
Common Vulnerabilities List
CVE-2024-24487
Summary

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the EXEC REBOOT SYSTEM command.

Publication Date April 16, 2024, 4:15 a.m.
Registration Date April 17, 2024, 10:02 a.m.
Last Update Nov. 21, 2024, 5:59 p.m.
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32955
Summary

SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 1:56 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32956
Summary

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 1:57 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32957
Summary

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded on the device without authentication.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 1:58 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32958
Summary

SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware update.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 2 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32959
Summary

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the traffic may be retrieved via man-in-the-middle attack.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 2 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32960
Summary

SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing the password by sending a crafted packet.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 2:01 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32961
Summary

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 2:02 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32962
Summary

SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 2:30 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32963
Summary

SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitrary script may be executed on the user's browser.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 2:09 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32964
Summary

SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the system configuration.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 2:29 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List
CVE-2026-32965
Summary

Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is connected to the network with the initial (factory-default) configuration, the device can be configured with the null string password.

Publication Date April 20, 2026, 1:16 p.m.
Registration Date April 21, 2026, 4:09 a.m.
Last Update April 23, 2026, 2:29 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:silextechnology:sd-330ac_firmware:*:*:*:*:*:*:*:* 1.50
cpe:2.3:a:silextechnology:amc_manager:*:*:*:*:*:*:*:* 5.1.0
Configuration2 or higher or less more than less than
Related information, measures and tools
Common Vulnerabilities List