Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
97021.9%CRITICAL

Related CVEs

7
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2026-28256A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.MEDIUM6.918.0%Mar 12, 2026
CVE-2026-28255A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.HIGH8.220.5%Mar 12, 2026
CVE-2026-28254A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.MEDIUM6.918.3%Mar 12, 2026
CVE-2026-28253A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service conditionHIGH8.722.3%Mar 12, 2026
CVE-2026-28252A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.CRITICAL9.212.0%Mar 12, 2026
CVE-2023-4212 ​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick. MEDIUM6.863.3%Aug 22, 2023
CVE-2021-38448The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.HIGH7.6Nov 22, 2021