Impact
A WebSocket service in the Acer System Monitoring component of NitroSense and PredatorSense was configured to listen on all network interfaces. This configuration may expose the service to unintended network access, potentially allowing unauthenticated remote participants to connect to the service.
Affected Systems
The vulnerability applies to the Acer System Monitoring component included with NitroSense and PredatorSense software. No specific version information is stated, so all current installations may be affected until a vendor update is released.
Risk and Exploitability
The CVSS score of 2.7 indicates a low severity impact, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local network access, requiring an attacker to be on the same network segment to reach the listening service.
OpenCVE Enrichment