CVE-2025-61480
Vanderbilt Industries · Acre Security SPC5300.000 Main Board
A vulnerability in the Vanderbilt Industries Acre Security SPC5300.000 Main Board allows a physically proximate attacker to trigger a denial of service using spoofed TCP FIN packets.
Executive summary
A high-severity denial of service vulnerability in the Vanderbilt Industries Acre Security SPC5300.000 Main Board allows unauthenticated attackers to disrupt system availability.
Vulnerability
The device fails to properly validate sequence or acknowledgment numbers in TCP FIN packets, allowing an unauthenticated attacker to cause a denial of service condition.
Business impact
Successful exploitation results in a denial of service, rendering the security system unresponsive. Given the CVSS score of 7.5, this high-severity flaw poses a significant operational risk, as critical security infrastructure could be taken offline by an attacker with physical proximity.
Remediation
Immediate Action: Contact Vanderbilt Industries support immediately to confirm if a firmware patch is available for the SPC5300.000 Main Board and apply it as soon as possible.
Proactive Monitoring: Monitor network traffic for anomalous TCP FIN packets directed at security hardware and review system logs for recurring service interruptions or unexpected reboots.
Compensating Controls: Restrict physical access to the network infrastructure supporting the SPC5300.000 units and utilize network segmentation to isolate the security management plane from untrusted segments.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a clear risk to the availability of critical security management hardware. Administrators should prioritize identifying all affected units within their environment and coordinate with the vendor to obtain remediation guidance or updated firmware to eliminate the underlying TCP stack deficiency.