← Back

Tracer Sc Firmware

tracer_sc_firmware

Vendor: Trane • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trane
2Tracer Concierge
Tracer Sc Firmware
Jun 17, 2026
Mar 12, 2026
6.9 MEDIUM· v4
9.8 CRITICAL· v3
N/A· v2
A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
1Trane
2Tracer Concierge
Tracer Sc Firmware
Jun 17, 2026
Mar 12, 2026
8.2 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
1Trane
2Tracer Concierge
Tracer Sc Firmware
Jun 17, 2026
Mar 12, 2026
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
1Trane
2Tracer Concierge
Tracer Sc Firmware
Jun 17, 2026
Mar 12, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition
1Trane
2Tracer Concierge
Tracer Sc Firmware
Jun 17, 2026
Mar 12, 2026
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.
1Trane
2Tracer Concierge
Tracer Sc Firmware
Jun 17, 2026
Oct 27, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.
1Trane
1Tracer Sc Firmware
Jun 17, 2026
Oct 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The affected product’s web application does not properly neutralize the input during webpage generation, which could allow an attacker to inject code in the input forms.