CVE-2025-61479 Overview
CVE-2025-61479 affects the Vanderbilt Industries and Acre Security SPC5300.000 Main Board version 3.14.1. The vulnerability allows a physically proximate attacker to trigger a denial of service condition. The SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session. An attacker with network access to the active session can replay valid payloads to disrupt the intrusion detection panel's operation.
Critical Impact
A physically proximate attacker can disrupt operation of SPC5300 intrusion panels by replaying application-layer payloads into an established TCP session, resulting in denial of service for the security system.
Affected Products
- Vanderbilt Industries SPC5300.000 Main Board v3.14.1
- Acre Security SPC5300.000 Main Board v3.14.1
- SPC Connect Pro software (session-handling component)
Discovery Timeline
- 2026-08-26 - CVE-2025-61479 published to NVD
- 2026-08-26 - Last updated in NVD database
Technical Details for CVE-2025-61479
Vulnerability Analysis
CVE-2025-61479 is a replay attack vulnerability in the SPC Connect Pro software that communicates with the SPC5300 Main Board. The software fails to reject duplicated application-layer payloads within an active TCP session. An attacker positioned on the local network path can capture legitimate messages and reinject them into the established session. The device processes these replayed payloads as valid, which drives the panel into a denial of service state.
The SPC5300 is a hybrid intrusion detection panel deployed in commercial and critical facility environments. A loss of availability affects alarm reporting, tamper detection, and operator visibility.
Root Cause
The root cause is missing anti-replay protection at the application layer. TCP session integrity alone does not prevent replay of authenticated or unauthenticated payloads by an attacker who can inject frames into an existing session. The protocol implementation lacks sequence validation, nonces, or timestamp checks that would detect duplicated messages. This aligns with weaknesses in the class of authentication and freshness controls for network protocols.
Attack Vector
Exploitation requires physical proximity or access to the network segment carrying SPC Connect Pro traffic. The attacker observes application-layer messages exchanged with the SPC5300 Main Board and replays selected payloads into the active TCP stream. Because the receiving endpoint accepts the replayed data, the panel enters a state that halts normal operation. No authentication credentials, user interaction, or software vulnerability chaining are required beyond session-level access.
See the NVA Registration Document for the original technical write-up.
Detection Methods for CVE-2025-61479
Indicators of Compromise
- Duplicate application-layer payloads observed within a single SPC Connect Pro TCP session
- Unexpected disconnects, reboots, or unresponsive states on SPC5300 panels
- Alarm reporting gaps or supervision failures reported by the central monitoring station
Detection Strategies
- Deploy network intrusion detection signatures that flag repeated identical application payloads within one TCP flow to the SPC5300
- Baseline normal SPC Connect Pro traffic patterns and alert on protocol anomalies or session hijack indicators
- Correlate panel availability events with packet-capture data on the operational technology (OT) segment
Monitoring Recommendations
- Enable session logging on SPC Connect Pro servers and forward logs to a central SIEM for anomaly analysis
- Monitor switch and firewall counters for unusual traffic to and from panel IP addresses
- Alert on physical tamper or link-state changes on network ports serving the intrusion panels
How to Mitigate CVE-2025-61479
Immediate Actions Required
- Restrict physical and logical access to network segments carrying SPC Connect Pro traffic
- Place SPC5300 panels and management servers on an isolated VLAN with strict access control lists
- Enforce port security and 802.1X on switch ports connecting panels and controllers
- Contact Vanderbilt Industries or Acre Security for vendor guidance on firmware updates addressing the replay condition
Patch Information
No vendor patch has been referenced in the published advisory data at the time of writing. Operators should review the NVA Registration Document and contact the vendor directly for remediation status for SPC5300.000 Main Board v3.14.1.
Workarounds
- Tunnel SPC Connect Pro traffic through an IPsec or TLS VPN that provides anti-replay windows and message authentication
- Segment intrusion detection infrastructure from general-purpose enterprise networks and wireless access
- Deploy physical controls such as locked communications cabinets and tamper-evident cabling to reduce proximity-based access
- Increase supervision poll frequency so that induced downtime is detected and escalated quickly by the monitoring station
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

