CVE-2025-61480

Vanderbilt Industries · Acre Security SPC5300.000 Main Board

A vulnerability in the Vanderbilt Industries Acre Security SPC5300.000 Main Board allows a physically proximate attacker to trigger a denial of service using spoofed TCP FIN packets.

Executive summary

A high-severity denial of service vulnerability in the Vanderbilt Industries Acre Security SPC5300.000 Main Board allows unauthenticated attackers to disrupt system availability.

Vulnerability

The device fails to properly validate sequence or acknowledgment numbers in TCP FIN packets, allowing an unauthenticated attacker to cause a denial of service condition.

Business impact

Successful exploitation results in a denial of service, rendering the security system unresponsive. Given the CVSS score of 7.5, this high-severity flaw poses a significant operational risk, as critical security infrastructure could be taken offline by an attacker with physical proximity.

Remediation

Immediate Action: Contact Vanderbilt Industries support immediately to confirm if a firmware patch is available for the SPC5300.000 Main Board and apply it as soon as possible.

Proactive Monitoring: Monitor network traffic for anomalous TCP FIN packets directed at security hardware and review system logs for recurring service interruptions or unexpected reboots.

Compensating Controls: Restrict physical access to the network infrastructure supporting the SPC5300.000 units and utilize network segmentation to isolate the security management plane from untrusted segments.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a clear risk to the availability of critical security management hardware. Administrators should prioritize identifying all affected units within their environment and coordinate with the vendor to obtain remediation guidance or updated firmware to eliminate the underlying TCP stack deficiency.

Sources