Executive brief
A security control device used to protect industrial facilities is vulnerable to a denial-of-service attack when an attacker with physical proximity sends specially crafted network packets. An attacker could disrupt the device's operation, potentially leaving the facility without proper security monitoring or access controls.
Technical details
The Vanderbilt Acre Security SPC5300.000 Main Board v.3.14.1 fails to properly validate the sequence and acknowledgment numbers on incoming TCP FIN packets. This allows a physically proximate attacker on the adjacent network to craft spoofed TCP FIN packets that can prematurely terminate active network connections. The vulnerability is a denial-of-service condition that disrupts legitimate network communication to the device. No patch information is currently available in the advisory.
Affected products
- Vanderbilt Industries Acre Security SPC5300.000 Main Board 3.14.1
Timeline
- 2026-08-26: disclosed