Vulnerability Details CVE-2021-38448
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 4.6
Products affected by CVE-2021-38448
-
cpe:2.3:a:trane:symbio_700:*
-
cpe:2.3:a:trane:symbio_800:*
-
cpe:2.3:h:trane:ascend_air-cooled_chiller_acr:-
-
cpe:2.3:h:trane:intellipak_1:-
-
cpe:2.3:h:trane:intellipak_2:-
-
cpe:2.3:h:trane:odyssey_split_systems:-