CVE-2025-61479
Vanderbilt Industries, Acre Security · SPC5300.000 Main Board
A vulnerability in the Vanderbilt Industries, Acre Security SPC5300.000 Main Board allows a physically proximate attacker to trigger a denial of service via replayed TCP application-layer payloads.
Executive summary
A high-severity denial of service vulnerability in the Vanderbilt Industries, Acre Security SPC5300.000 Main Board could allow an attacker to disrupt system availability through TCP session manipulation.
Vulnerability
The flaw resides in the SPC Connect Pro software, which fails to properly validate application-layer payloads. An unauthenticated attacker with physical proximity can inject replayed payloads into an active TCP session to cause a system denial of service.
Business impact
The ability for an attacker to cause a denial of service directly impacts the operational continuity of security or management hardware. Given the CVSS score of 7.5, this high-severity vulnerability poses a significant risk to system availability, potentially rendering critical infrastructure unresponsive and requiring manual intervention to restore service.
Remediation
Immediate Action: Contact the vendor immediately to determine if a firmware update or security patch is available for the SPC5300.000 Main Board.
Proactive Monitoring: Monitor network traffic for anomalous TCP session behavior or repeated connection attempts directed at the SPC Connect Pro interface.
Compensating Controls: Restrict physical access to the network infrastructure hosting the affected main board and segment the network to limit the reach of unauthorized devices.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing the Vanderbilt Industries, Acre Security SPC5300.000 Main Board should prioritize verifying the current firmware version and coordinating with the vendor for remediation guidance. Due to the high potential for service disruption, implementing strict physical access controls is recommended as a primary measure until a patch is confirmed and applied.