Critical severity9.9NVD Advisory· Published Oct 27, 2021· Updated Jun 17, 2026
CVE-2021-38450
CVE-2021-38450
Description
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:trane:tracer_concierge:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:trane:tracer_concierge:*:*:*:*:*:*:*:*range: <5.5
- cpe:2.3:a:trane:tracer_concierge:5.5:-:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc\+_firmware:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:trane:tracer_sc\+_firmware:*:*:*:*:*:*:*:*range: <5.5
- cpe:2.3:o:trane:tracer_sc\+_firmware:5.5:-:*:*:*:*:*:*
- cpe:2.3:o:trane:tracer_sc_firmware:*:*:*:*:*:*:*:*range: <4.4
- cpe:2.3:o:trane:tracer_sc_firmware:4.4:-:*:*:*:*:*:*
- Range: All
Patches
Vulnerability mechanics
References
1- us-cert.cisa.gov/ics/advisories/icsa-21-266-02nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.