Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-61479

CVE-2025-61479: Vanderbilt SPC5300 Board DOS Vulnerability

CVE-2025-61479 is a denial of service flaw in Vanderbilt Industries Acre Security SPC5300.000 Main Board that allows physically proximate attackers to disrupt operations. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2025-61479 Overview

CVE-2025-61479 affects the Vanderbilt Industries and Acre Security SPC5300.000 Main Board version 3.14.1. The vulnerability allows a physically proximate attacker to trigger a denial of service condition. The SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session. An attacker with network access to the active session can replay valid payloads to disrupt the intrusion detection panel's operation.

Critical Impact

A physically proximate attacker can disrupt operation of SPC5300 intrusion panels by replaying application-layer payloads into an established TCP session, resulting in denial of service for the security system.

Affected Products

  • Vanderbilt Industries SPC5300.000 Main Board v3.14.1
  • Acre Security SPC5300.000 Main Board v3.14.1
  • SPC Connect Pro software (session-handling component)

Discovery Timeline

  • 2026-08-26 - CVE-2025-61479 published to NVD
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2025-61479

Vulnerability Analysis

CVE-2025-61479 is a replay attack vulnerability in the SPC Connect Pro software that communicates with the SPC5300 Main Board. The software fails to reject duplicated application-layer payloads within an active TCP session. An attacker positioned on the local network path can capture legitimate messages and reinject them into the established session. The device processes these replayed payloads as valid, which drives the panel into a denial of service state.

The SPC5300 is a hybrid intrusion detection panel deployed in commercial and critical facility environments. A loss of availability affects alarm reporting, tamper detection, and operator visibility.

Root Cause

The root cause is missing anti-replay protection at the application layer. TCP session integrity alone does not prevent replay of authenticated or unauthenticated payloads by an attacker who can inject frames into an existing session. The protocol implementation lacks sequence validation, nonces, or timestamp checks that would detect duplicated messages. This aligns with weaknesses in the class of authentication and freshness controls for network protocols.

Attack Vector

Exploitation requires physical proximity or access to the network segment carrying SPC Connect Pro traffic. The attacker observes application-layer messages exchanged with the SPC5300 Main Board and replays selected payloads into the active TCP stream. Because the receiving endpoint accepts the replayed data, the panel enters a state that halts normal operation. No authentication credentials, user interaction, or software vulnerability chaining are required beyond session-level access.

See the NVA Registration Document for the original technical write-up.

Detection Methods for CVE-2025-61479

Indicators of Compromise

  • Duplicate application-layer payloads observed within a single SPC Connect Pro TCP session
  • Unexpected disconnects, reboots, or unresponsive states on SPC5300 panels
  • Alarm reporting gaps or supervision failures reported by the central monitoring station

Detection Strategies

  • Deploy network intrusion detection signatures that flag repeated identical application payloads within one TCP flow to the SPC5300
  • Baseline normal SPC Connect Pro traffic patterns and alert on protocol anomalies or session hijack indicators
  • Correlate panel availability events with packet-capture data on the operational technology (OT) segment

Monitoring Recommendations

  • Enable session logging on SPC Connect Pro servers and forward logs to a central SIEM for anomaly analysis
  • Monitor switch and firewall counters for unusual traffic to and from panel IP addresses
  • Alert on physical tamper or link-state changes on network ports serving the intrusion panels

How to Mitigate CVE-2025-61479

Immediate Actions Required

  • Restrict physical and logical access to network segments carrying SPC Connect Pro traffic
  • Place SPC5300 panels and management servers on an isolated VLAN with strict access control lists
  • Enforce port security and 802.1X on switch ports connecting panels and controllers
  • Contact Vanderbilt Industries or Acre Security for vendor guidance on firmware updates addressing the replay condition

Patch Information

No vendor patch has been referenced in the published advisory data at the time of writing. Operators should review the NVA Registration Document and contact the vendor directly for remediation status for SPC5300.000 Main Board v3.14.1.

Workarounds

  • Tunnel SPC Connect Pro traffic through an IPsec or TLS VPN that provides anti-replay windows and message authentication
  • Segment intrusion detection infrastructure from general-purpose enterprise networks and wireless access
  • Deploy physical controls such as locked communications cabinets and tamper-evident cabling to reduce proximity-based access
  • Increase supervision poll frequency so that induced downtime is detected and escalated quickly by the monitoring station

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.