Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and PredatorSense Software
8Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 1.2epss 0.1%
probabilidade de exploração
0.1%top 100% das CVEs
exploração observada
nãonenhuma fonte reporta
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U
Produtos afetados
Acer · System Monitoring