Impact
The vulnerability arises from a hard‑coded AES encryption key that is embedded within the Acer System Monitoring component used by NitroSense and PredatorSense. Because the key is stored in the binary, an attacker who can obtain the key may decrypt protected data or perform functions that would normally require a valid key, leading to unauthorized access to confidential information or the execution of privileged actions. This weakness is classified as CWE‑321, representing improper key management. The CVSS score of 1.2 indicates a low‑impact flaw.
Affected Systems
The affected product is Acer System Monitoring, which is part of NitroSense and PredatorSense. Systems running NitroSense prior to version 5.2.84 or PredatorSense prior to version 5.2.109 are vulnerable. The vendor’s official recommendation is to upgrade to NitroSense v5.2.84 or later, or PredatorSense v5.2.109 or later. These versions replace the hard‑coded key with a proper key handling mechanism.
Risk and Exploitability
The EPSS score is less than 1 %, and the vulnerability is not listed in the CISA KEV catalogue, implying that exploitation is unlikely at present. Based on the description, it is inferred that the attack vector is local; an attacker must already have local access to the system to exploit the hard‑coded key. If an attacker gains a local foothold, they could read encrypted data or trigger privileged actions, but remote exploitation or privilege escalation is not supported by the current information.
OpenCVE Enrichment