Impact
An attacker who can physically reach the device may exploit a flaw in the SPC Connect Pro software that accepts application‑layer payloads replayed into an active TCP session. By sending previously captured data to the firmware, the attacker can force the board to repeatedly process the payload, causing the system to halt or become unresponsive and resulting in a denial of service. The weakness is identified as CWE-294, indicating that unlawful reuse of data leads to a system malfunction.
Affected Systems
The vulnerability affects the Acre Security SPC5300.000 Main Board, specifically firmware version 3.14.1. Although no official CNA vendor name is listed, the description attributes the product to Vanderbilt Industries and Acre Security. Only the mentioned firmware build is known to contain the flaw.
Risk and Exploitability
This does not depend on network reachability; the attacker requires close physical proximity to the board to capture or inject the payload. The EPSS score of less than 1% signals a low probability of exploitation in the wild, yet the CVSS score of 7.5 reflects a high severity if the vulnerability is leveraged. Because the impact is a full service interruption and the flaw can be triggered by replaying data already observed on a legitimate session, the risk remains significant for any device without updating or containing additional operational security controls. The vulnerability is not listed in CISA’s KEV catalog, so no active exploitation campaigns are known, but the potential for localized denial of service warrants attention.
OpenCVE Enrichment