CVE-2026-32964
בינונית 6.5
תיאור (מקור, אנגלית)
SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the system configuration.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L - CVSS 4.0
-
6.9 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-28/7/2026
- CWE
- CWE-93
מוצרים מושפעים
silextechnology: sd-330ac firmware; silextechnology: sd-330ac; silextechnology: amc manager
קישורים
- https://www.silex.jp/support/security-advisories/2026-001 Vendor Advisory
- https://www.silex.jp/support/security-advisories/en/2026-001 Vendor Advisory
- https://jvn.jp/en/vu/JVNVU94271449/ Third Party Advisory