VYPR

Tracer Sc

by Track\+

CVEs (9)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-4526Hig0.497.50.00Sep 19, 2016ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.
CVE-2016-0870Med0.345.30.01Sep 19, 2016The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.
CVE-2026-282560.000.00Mar 12, 2026A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
CVE-2026-282550.000.00Mar 12, 2026A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
CVE-2026-282540.000.00Mar 12, 2026A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
CVE-2026-282530.000.00Mar 12, 2026A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition
CVE-2026-282520.000.00Mar 12, 2026A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.
CVE-2021-384500.000.00Oct 27, 2021The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.
CVE-2021-425340.000.00Oct 22, 2021The affected product’s web application does not properly neutralize the input during webpage generation, which could allow an attacker to inject code in the input forms.