Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and PredatorSense Software
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 1.2epss 0.1%
exploitation probability
0.1%top 100% of all CVEs
observed exploitation
nono source reports it
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U
Affected products
Acer · System Monitoring