Impact
An attacker in close physical proximity can exploit a flaw in the Acre Security SPC5300.000 Main Board v3.14.1. The SPC Connect Pro software accepts previously captured application‑layer payloads injected into an active TCP session, allowing the attacker to replay them and cause the system to stop responding, resulting in a denial of service.
Affected Systems
The affected product is Vanderbilt Industries' Acre Security SPC5300.000 Main Board running firmware version 3.14.1.
Risk and Exploitability
The vulnerability is local and requires physical access, so its exploitation probability is dependent on an attacker’s proximity. No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw results in a full service interruption, the risk is high even if the likelihood cannot be quantified. The attacker would need to read or capture a valid payload, inject it into an existing TCP session, and force the firmware to process it repeatedly. A vulnerable device without an update is therefore a target for an attacker capable of proximity or tampering.
OpenCVE Enrichment