Impact
The vulnerability lies in the Minor Board’s TCP stack, which does not validate sequence or acknowledgment numbers for FIN packets. An attacker who can physically reach the device can send crafted duplicate FIN packets that exhaust the device’s TCP resources or lock the stack into an invalid state, causing legitimate traffic to be dropped and the system to become unusable. The flaw can be triggered without privilege escalation, so the primary consequence is availability loss for the affected hardware.
Affected Systems
The affected system is the Acre Security SPC5300.000 Main Board version 3.14.1 produced by Vanderbilt Industries. No other vendors, products, or firmware variants are enumerated in the available data.
Risk and Exploitability
The CVSS score is not publicly disclosed, and EPSS data is unavailable, so the exact likelihood cannot be quantified. The flaw requires a physically proximate attacker and does not rely on network exposure, which lowers its remote exploitability. While the denial of service can be easily observed for any network that relies on the board’s traffic handling, the absence of the vulnerability from CISA’s KEV catalog suggests that no widely known exploits are published yet. Nonetheless, the lack of a fix means administrators should remain alert for network disruptions caused by this attack vector.
OpenCVE Enrichment