Trane Tracer SC等都是美国Trane公司的产品。Trane Tracer SC是一个监控与自动化管理的楼宇控制器。Trane Tracer SC+是一个监控与自动化管理的楼宇控制器。Trane Tracer Concierge是一个监控和管理建筑暖通空调设备运行状态的楼宇管理软件。 Trane多款产品存在加密问题漏洞,该漏洞源于使用有缺陷或高风险的加密算法,可能导致攻击者绕过身份验证并获得设备root级访问权限。以下产品受到影响:Trane Tracer SC、Tracer SC+和Trac
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Trane | Tracer SC | 0 ~ v4.4 SP7 | - |
|
| Trane | Tracer SC+ | 0 ~ v6.3.2310 | - |
|
| Trane | Tracer Concierge | 0 ~ v6.3.2310 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28253 | Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, | |
| CVE-2026-28254 | Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge | |
| CVE-2026-28255 | Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Con | |
| CVE-2026-28256 | Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Con |
No comments yet