VYPR

Tracer Concierge

by Track\+

CVEs (6)

  • CVE-2026-28256CriMar 12, 2026
    risk 0.64cvss 9.8epss 0.00

    A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

  • CVE-2026-28255CriMar 12, 2026
    risk 0.64cvss 9.8epss 0.00

    A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

  • CVE-2026-28252CriMar 12, 2026
    risk 0.64cvss 9.8epss 0.00

    A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.

  • CVE-2021-38450CriOct 27, 2021
    risk 0.64cvss 9.9epss 0.01

    The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

  • CVE-2026-28254HigMar 12, 2026
    risk 0.49cvss 7.5epss 0.00

    A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.

  • CVE-2026-28253HigMar 12, 2026
    risk 0.49cvss 7.5epss 0.00

    A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition