Sceawere

Vulnerability Detail

CVE-2025-61479UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Acre SPC5300 Replay DoS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
1d ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-26T21:16:37.820Z",
  "pubdate": "2026-08-26T21:16:37.820Z",
  "executiveSummary": "A critical vulnerability identified in the Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 enables a physically proximate attacker to trigger a denial-of-service (DoS) condition.\nThe vulnerability stems from insufficient validation of application-layer payloads within the SPC Connect Pro software ecosystem.\nBy capturing and replaying valid application-layer traffic into an established TCP session, an unauthorized actor can disrupt system availability.\nThe primary impact is the loss of operational integrity and system downtime, posing a significant risk to the availability of the security controller.\nExploitation is contingent upon the attacker gaining physical proximity to the target network or device infrastructure to intercept and inject packets into an active TCP stream.\nSuccessful execution requires the ability to perform packet sniffing and session injection, emphasizing the necessity of physical security controls for the controller hardware.",
  "technicalDetails": "The vulnerability resides in the communication handling logic of the SPC Connect Pro software running on the Vanderbilt Industries, Acre Security SPC5300.000 Main Board (v.3.14.1).\nThe root cause is the lack of cryptographic nonces, sequence numbering, or timestamping mechanisms to ensure the freshness and integrity of application-layer messages transmitted over TCP.\nThe protocol stack fails to differentiate between legitimate subsequent transmissions and replayed packets within the context of an existing, authenticated TCP session.\nThe attack flow begins with the attacker positioning themselves within the local network segment or leveraging a direct physical connection to the controller. Using traffic analysis tools, the attacker intercepts existing application-layer payloads transmitted during a standard management session.\nOnce a valid sequence of application-layer commands is captured, the attacker injects these payloads into the active TCP session. Because the SPC Connect Pro application lacks a mechanism to detect that these payloads have been previously processed, the controller accepts and attempts to execute the replayed commands.\nThe specific injection of malicious or redundant application-layer sequences causes the firmware to enter an unstable state, crash, or enter a hang condition, effectively resulting in a denial of service.\nSince the vulnerability exploits the application-layer handling, the TCP connection itself remains stable, but the internal application process becomes unresponsive.\nThis behavior indicates that the application logic does not implement adequate state tracking or request-id validation, allowing an attacker to bypass intended authentication logic by re-using previously valid transaction sequences.\nBecause the vulnerability requires an active TCP session, the attacker must either wait for an administrator to establish a connection or force a connection through secondary means.\nPost-exploitation impact is limited to the denial of service of the security controller, which may require a hardware-level power cycle to restore functionality.\nThe lack of application-level message sequencing remains a persistent issue as long as the underlying firmware logic fails to validate the originality and sequential integrity of incoming data streams."
}
CVE-2025-61479: Acre SPC5300 Replay DoS Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere