VYPR

Tracer Sc+

by Trane

CVEs (7)

  • CVE-2016-0870MedSep 19, 2016
    risk 0.35cvss 5.3epss 0.01

    The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.

  • CVE-2026-28256Mar 12, 2026
    risk 0.00cvss epss 0.00

    A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

  • CVE-2026-28255Mar 12, 2026
    risk 0.00cvss epss 0.00

    A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

  • CVE-2026-28254Mar 12, 2026
    risk 0.00cvss epss 0.00

    A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.

  • CVE-2026-28253Mar 12, 2026
    risk 0.00cvss epss 0.00

    A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition

  • CVE-2026-28252Mar 12, 2026
    risk 0.00cvss epss 0.00

    A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.

  • CVE-2021-38450Oct 27, 2021
    risk 0.00cvss epss 0.01

    The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

VYPR — Vulnerability Intelligence