Filtered by vendor Trane Subscriptions
Filtered by product Tracer Sc Subscriptions
Total 9 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-28252 1 Trane 2 Tracer Concierge, Tracer Sc 2026-03-13 N/A
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.
CVE-2026-28253 1 Trane 2 Tracer Concierge, Tracer Sc 2026-03-13 N/A
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition
CVE-2026-28254 1 Trane 2 Tracer Concierge, Tracer Sc 2026-03-13 N/A
A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
CVE-2026-28255 1 Trane 2 Tracer Concierge, Tracer Sc 2026-03-13 N/A
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
CVE-2026-28256 1 Trane 2 Tracer Concierge, Tracer Sc 2026-03-13 N/A
A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
CVE-2016-0870 1 Trane 1 Tracer Sc 2025-04-12 N/A
The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.
CVE-2016-4526 1 Trane 1 Tracer Sc 2025-04-12 N/A
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.
CVE-2021-42534 1 Trane 2 Tracer Sc, Tracer Sc Firmware 2024-11-21 6.3 Medium
The affected product’s web application does not properly neutralize the input during webpage generation, which could allow an attacker to inject code in the input forms.
CVE-2021-38450 1 Trane 5 Tracer Concierge, Tracer Sc, Tracer Sc\+ and 2 more 2024-11-21 9.9 Critical
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.