Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tracer Sc Firmware CRITICAL 9.8
CVE-2026-28252

A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypa…

Fix: 6.3.2310+
Fix from $2,300 2026-03-12
Tracer Sc Firmware CRITICAL 9.8
CVE-2026-28255

A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive info…

Fix: 6.3.2310+
Fix from $2,300 2026-03-12
Tracer Sc\+ Firmware CRITICAL 9.8
CVE-2026-28256

A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclo…

Fix: 6.3.2310+
Fix from $2,300 2026-03-12
Tracer Sc Firmware HIGH 7.5
CVE-2026-28253

A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attac…

Fix: 6.3.2310+
Fix from $1,950 2026-03-12
Tracer Sc Firmware HIGH 7.5
CVE-2026-28254

A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitiv…

Fix: 6.3.2310+
Fix from $1,950 2026-03-12
Xl824 Firmware MEDIUM 6.8
CVE-2023-4212

​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as …

Fix: after 5.9.8
Fix from $1,600 2023-08-22
Symbio 700 HIGH 7.6
CVE-2021-38448

The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended c…

Fix: 1.00.0023 / 1.10.0010+
Fix from $1,950 2021-11-22
Tracer Concierge HIGH 8.8
CVE-2021-38450

The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended c…

Fix: 4.4 / 5.5+
Fix from $1,950 2021-10-27
Tracer Sc Firmware MEDIUM 6.1
CVE-2021-42534

The affected product’s web application does not properly neutralize the input during webpage generation, which could allow an attacker to inject code…

Fix: after 3.8
Fix from $1,600 2021-10-22
Comfortlink Ii Firmware CRITICAL 9.8
CVE-2015-2867

A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.

No fix yet
Fix from $2,300 2017-01-06
Comfortlink Ii Firmware CRITICAL 9.8
CVE-2015-2868EPSS 7%

An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can conn…

No fix yet
Fix from $2,300 2017-01-06
Tracer Sc HIGH 7.5
CVE-2016-4526

ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.

Fix: after 4.2.1134
Fix from $1,950 2016-09-19
Tracer Sc MEDIUM 5.3
CVE-2016-0870

The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.

Fix: after 4.2.1134
Fix from $1,600 2016-09-19