Description
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized access to service functionality may be possible.
Published: 2026-09-17
Score: 1.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Patch Update
AI Analysis

Impact

The flaw allows an attacker to establish a WebSocket connection to Acer’s System Monitoring component without providing any credentials, exposing service functionality that was intended to be protected. This unauthorized access is an input‑validation type weakness (CWE‑306) and could let an adversary read monitoring data or trigger monitoring actions, thereby breaching confidentiality or integrity of the monitored system.

Affected Systems

The vulnerability exists in earlier builds of NitroSense and PredatorSense that are shipped with Acer System Monitoring. Acer specifically recommends upgrading to NitroSense v5.2.84 or PredatorSense v5.2.109 to eliminate the issue. All releases prior to these versions remain potentially exposed.

Risk and Exploitability

The CVSS score of 1.2 reflects low severity, and the EPSS score of less than 1% indicates that exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires network reachability to the WebSocket port; an attacker can send an unauthenticated handshake and gain functional access to the monitoring service, assuming no additional network or application layer controls are in place.

Generated by OpenCVE AI on September 18, 2026 at 00:27 UTC.

Remediation

Vendor Solution

Update to one of the following versions or later: * NitroSense v5.2.84 * PredatorSense v5.2.109


OpenCVE Recommended Actions

  • Update NitroSense to v5.2.84 or PredatorSense to v5.2.109
  • If a patch cannot be applied immediately, block unauthenticated WebSocket traffic from untrusted networks using firewall or NAT rules
  • Confirm that the WebSocket handshake in the configuration requires authentication and monitor logs for unauthorized connection attempts

Generated by OpenCVE AI on September 18, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Acer
Acer system Monitoring
Vendors & Products Acer
Acer system Monitoring

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized access to service functionality may be possible.
Title Authentication Vulnerability in NitroSense and PredatorSense Software
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U'}


Subscriptions

Acer System Monitoring
cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-09-17T12:25:51.670Z

Reserved: 2026-06-05T07:22:32.054Z

Link: CVE-2026-50608

cve-icon Vulnrichment

Updated: 2026-09-17T12:25:41.506Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T09:16:41.253

Modified: 2026-09-18T16:25:08.493

Link: CVE-2026-50608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:02:49Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function