Description
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.
Published: 2026-08-26
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

An attacker who can physically reach the device may exploit a flaw in the SPC Connect Pro software that accepts application‑layer payloads replayed into an active TCP session. By sending previously captured data to the firmware, the attacker can force the board to repeatedly process the payload, causing the system to halt or become unresponsive and resulting in a denial of service. The weakness is identified as CWE-294, indicating that unlawful reuse of data leads to a system malfunction.

Affected Systems

The vulnerability affects the Acre Security SPC5300.000 Main Board, specifically firmware version 3.14.1. Although no official CNA vendor name is listed, the description attributes the product to Vanderbilt Industries and Acre Security. Only the mentioned firmware build is known to contain the flaw.

Risk and Exploitability

This does not depend on network reachability; the attacker requires close physical proximity to the board to capture or inject the payload. The EPSS score of less than 1% signals a low probability of exploitation in the wild, yet the CVSS score of 7.5 reflects a high severity if the vulnerability is leveraged. Because the impact is a full service interruption and the flaw can be triggered by replaying data already observed on a legitimate session, the risk remains significant for any device without updating or containing additional operational security controls. The vulnerability is not listed in CISA’s KEV catalog, so no active exploitation campaigns are known, but the potential for localized denial of service warrants attention.

Generated by OpenCVE AI on August 28, 2026 at 18:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update that addresses the replay‑handling flaw, obtained from the vendor’s support portal or official release channel.
  • Secure the device physically by enclosing it in a locked environment and controlling access with badge or biometric systems to prevent unauthorized proximity.
  • Segment the board’s network interface to isolate it from untrusted traffic, monitor for repeated payload patterns, and consider disabling or restricting the feature that allows application‑layer payload injection if it is not essential for operational use.

Generated by OpenCVE AI on August 28, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Replayed Payloads on Acre Security Main Board

Fri, 28 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Replayable Payload Injection in Acre Security Main Board
Weaknesses CWE-20
CWE-400

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-294
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Replayable Payload Injection in Acre Security Main Board
Weaknesses CWE-20
CWE-400

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T17:54:51.901Z

Reserved: 2025-09-26T00:00:00.000Z

Link: CVE-2025-61479

cve-icon Vulnrichment

Updated: 2026-08-27T17:54:36.006Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-26T21:16:37.820

Modified: 2026-09-09T16:03:22.897

Link: CVE-2025-61479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T18:30:08Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay