Vulnerabilities
Vulnerable Software
Trane:  >> Tracer Sc+ Firmware  Security Vulnerabilities
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.
CVSS Score
9.8
EPSS Score
0.0
Published
2026-03-12
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition
CVSS Score
7.5
EPSS Score
0.001
Published
2026-03-12
A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
CVSS Score
7.5
EPSS Score
0.001
Published
2026-03-12
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
CVSS Score
9.8
EPSS Score
0.0
Published
2026-03-12
A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
CVSS Score
9.8
EPSS Score
0.0
Published
2026-03-12
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.
CVSS Score
9.9
EPSS Score
0.003
Published
2021-10-27


Contact Us

Shodan ® - All rights reserved