Acer
Acer Nitrosense: vulnerabilidades y CVE
Acer Nitrosense tiene 13 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses13
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-50228 | Media (6.1) | 0.13% | — | 23 sept 2026 | An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is… |
| CVE-2026-50227 | Media (6.1) | 0.35% | — | 23 sept 2026 | An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc… |
| CVE-2026-50610 | Alta (7.4) | 0.13% | — | 17 sept 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able… |
| CVE-2026-50609 | Alta (7.4) | 0.13% | — | 17 sept 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow an authenticated… |
| CVE-2026-50608 | Baja (1.2) | 0.21% | — | 17 sept 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing… |
| CVE-2026-50607 | Baja (2.7) | 0.43% | — | 17 sept 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the… |
| CVE-2026-50606 | Baja (1.2) | 0.10% | — | 17 sept 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software.… |
| CVE-2026-50605 | Alta (7.4) | 0.13% | — | 17 sept 2026 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated local user to… |
| CVE-2026-50604 | Media (4.9) | 0.21% | — | 17 sept 2026 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the… |
| CVE-2026-50603 | Media (4.9) | 0.10% | — | 17 sept 2026 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under… |
| CVE-2026-9789 | Alta (8.5) | 0.15% | — | 28 may 2026 | A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access… |
| CVE-2026-9489 | Alta (8.5) | 0.16% | — | 25 may 2026 | NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is… |
| CVE-2026-8069 | Alta (8.5) | 0.17% | — | 8 may 2026 | PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.