Impact
A flaw in the socket handshake of the Acer Agent Service for NitroSense and PredatorSense allows a remote party to establish a connection without authenticating. The missing validation can expose functionality that should be restricted, creating a risk of unauthorized operations against the service.
Affected Systems
All Acer Agent Service installations bundled with NitroSense and PredatorSense, including versions older than NitroSense v5.2.84 and PredatorSense v5.2.109. The vulnerability applies to the component that manages incoming socket connections.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. Because the flaw is an authentication bypass (CWE‑306), an attacker only needs the ability to reach the service over the network; no additional privileges or code execution are required. The likely attack vector is an inbound network connection to the Agent Service port, inferred from the description that the socket handshake does not require authentication. The vulnerability is not listed in the CISA KEV catalog, further indicating that widespread exploitation has not been observed yet. Nonetheless, the potential to gain unauthorized access to privileged service functionality warrants prompt remediation.
OpenCVE Enrichment