Description
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the Minor Board’s TCP stack, which does not validate sequence or acknowledgment numbers for FIN packets. An attacker who can physically reach the device can send crafted duplicate FIN packets that exhaust the device’s TCP resources or lock the stack into an invalid state, causing legitimate traffic to be dropped and the system to become unusable. The flaw can be triggered without privilege escalation, so the primary consequence is availability loss for the affected hardware.

Affected Systems

The affected system is the Acre Security SPC5300.000 Main Board version 3.14.1 produced by Vanderbilt Industries. No other vendors, products, or firmware variants are enumerated in the available data.

Risk and Exploitability

The CVSS score is not publicly disclosed, and EPSS data is unavailable, so the exact likelihood cannot be quantified. The flaw requires a physically proximate attacker and does not rely on network exposure, which lowers its remote exploitability. While the denial of service can be easily observed for any network that relies on the board’s traffic handling, the absence of the vulnerability from CISA’s KEV catalog suggests that no widely known exploits are published yet. Nonetheless, the lack of a fix means administrators should remain alert for network disruptions caused by this attack vector.

Generated by OpenCVE AI on August 26, 2026 at 22:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied firmware update for the Acre Security SPC5300 Main Board that addresses the TCP sequence validation issue.
  • Reboot the device to clear any corrupted TCP state and resume normal operation.
  • Configure network perimeter defenses—such as ACLs or firewalls—to filter out suspicious TCP FIN packets from untrusted sources.
  • Monitor device logs for repeated FIN packet attempts and verify that the denial of service no longer occurs.

Generated by OpenCVE AI on August 26, 2026 at 22:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Spoofed TCP FIN Packets on Acre Security SPC5300 Main Board
Weaknesses CWE-20

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-26T20:40:03.287Z

Reserved: 2025-09-26T00:00:00.000Z

Link: CVE-2025-61480

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T21:16:37.937

Modified: 2026-08-26T21:16:37.937

Link: CVE-2025-61480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation