Executive brief
The Acre Security SPC5300.000 Main Board is a physical access control system used to manage building security and restrict entry to facilities. An attacker with physical proximity to the device can replay network packets to cause a denial of service, disrupting access control operations and potentially preventing legitimate users from entering secured areas.
Technical details
This vulnerability involves a replay attack against the SPC Connect Pro software that manages the SPC5300.000 Main Board. The software accepts replayed application-layer payloads injected into active TCP sessions without proper validation or cryptographic protection, allowing an attacker with network or physical access to inject previously captured network traffic. An attacker with physical proximity to the network can intercept and replay legitimate TCP packets to cause a denial of service condition, disrupting the access control system. Patches or fixes are not mentioned in the available advisory information.
Affected products
- Vanderbilt Industries Acre Security SPC5300.000 Main Board v.3.14.1
Timeline
- 2026-08-26: disclosed