Description
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.
Published: 2026-09-17
Score: 1.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Potential Local Information Disclosure and Unauthorized Actions
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from a hard‑coded AES encryption key that is embedded within the Acer System Monitoring component used by NitroSense and PredatorSense. Because the key is stored in the binary, an attacker who can obtain the key may decrypt protected data or perform functions that would normally require a valid key, leading to unauthorized access to confidential information or the execution of privileged actions. This weakness is classified as CWE‑321, representing improper key management. The CVSS score of 1.2 indicates a low‑impact flaw.

Affected Systems

The affected product is Acer System Monitoring, which is part of NitroSense and PredatorSense. Systems running NitroSense prior to version 5.2.84 or PredatorSense prior to version 5.2.109 are vulnerable. The vendor’s official recommendation is to upgrade to NitroSense v5.2.84 or later, or PredatorSense v5.2.109 or later. These versions replace the hard‑coded key with a proper key handling mechanism.

Risk and Exploitability

The EPSS score is less than 1 %, and the vulnerability is not listed in the CISA KEV catalogue, implying that exploitation is unlikely at present. Based on the description, it is inferred that the attack vector is local; an attacker must already have local access to the system to exploit the hard‑coded key. If an attacker gains a local foothold, they could read encrypted data or trigger privileged actions, but remote exploitation or privilege escalation is not supported by the current information.

Generated by OpenCVE AI on September 18, 2026 at 00:52 UTC.

Remediation

Vendor Solution

Update to one of the following versions or later: * NitroSense v5.2.84 * PredatorSense v5.2.109


OpenCVE Recommended Actions

  • Upgrade NitroSense to version 5.2.84 or later, or PredatorSense to version 5.2.109 or later, to remove the hard‑coded AES key.
  • Limit local user privileges on the monitoring component by enforcing the principle of least privilege; run the component under a non‑elevated account and restrict filesystem access.
  • Configure the operating system’s access control lists to prevent unauthorized reading of the monitoring component’s configuration files and binaries, ensuring only the system account can read them.

Generated by OpenCVE AI on September 18, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Acer
Acer system Monitoring
Vendors & Products Acer
Acer system Monitoring

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.
Title Hard-coded Encryption Key Vulnerability in Acer System Monitoring for NitroSense and PredatorSense Software
Weaknesses CWE-321
References
Metrics cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U'}


Subscriptions

Acer System Monitoring
cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-09-17T12:30:03.105Z

Reserved: 2026-06-05T07:22:32.054Z

Link: CVE-2026-50606

cve-icon Vulnrichment

Updated: 2026-09-17T12:29:45.007Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T08:17:01.177

Modified: 2026-09-18T16:25:08.493

Link: CVE-2026-50606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:52Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key