Impact
The flaw allows an attacker to establish a WebSocket connection to Acer’s System Monitoring component without providing any credentials, exposing service functionality that was intended to be protected. This unauthorized access is an input‑validation type weakness (CWE‑306) and could let an adversary read monitoring data or trigger monitoring actions, thereby breaching confidentiality or integrity of the monitored system.
Affected Systems
The vulnerability exists in earlier builds of NitroSense and PredatorSense that are shipped with Acer System Monitoring. Acer specifically recommends upgrading to NitroSense v5.2.84 or PredatorSense v5.2.109 to eliminate the issue. All releases prior to these versions remain potentially exposed.
Risk and Exploitability
The CVSS score of 1.2 reflects low severity, and the EPSS score of less than 1% indicates that exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires network reachability to the WebSocket port; an attacker can send an unauthenticated handshake and gain functional access to the monitoring service, assuming no additional network or application layer controls are in place.
OpenCVE Enrichment