Skip to content
Noroxi

Trane records

13 published records for vendor trane.

All records

13 records
  • An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service.

    CriticalCVSS 9.8No exploitEPSS 7%

    trane · comfortlink ii firmwareJan 6, 2017

  • A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.

    CriticalCVSS 9.8No exploitEPSS 5%

    trane · comfortlink ii firmwareJan 6, 2017

  • Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge

    CriticalCVSS 9.2No exploitEPSS 0%

    trane · tracer sc firmwareMar 12, 2026

  • Trane Tracer Code Injection

    HighCVSS 8.8No exploitEPSS 1%

    trane · tracer conciergeOct 26, 2021

  • Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge

    HighCVSS 8.7No exploitEPSS 1%

    trane · tracer sc firmwareMar 12, 2026

  • Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge

    HighCVSS 8.2No exploitEPSS 0%

    trane · tracer sc firmwareMar 12, 2026

  • CVE-2016-4526
    30Monitor

    ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.

    HighCVSS 7.5No exploitEPSS 0%

    trane · tracer scSep 18, 2016

  • Trane Symbio Improper Control of Generation of Code

    HighCVSS 7.6No exploitEPSS 0%

    trane · symbio 700Nov 22, 2021

  • CVE-2023-4212
    27Monitor

    Trane Thermostats Injection

    MediumCVSS 6.8No exploitEPSS 1%

    trane · xl824 firmwareAug 22, 2023

  • Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge

    MediumCVSS 6.9No exploitEPSS 0%

    trane · tracer sc\+ firmwareMar 12, 2026

  • Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge

    MediumCVSS 6.9No exploitEPSS 0%

    trane · tracer sc firmwareMar 12, 2026

  • Trane Building Automation Controllers Cross-site Scripting

    MediumCVSS 6.1No exploitEPSS 1%

    trane · tracer sc firmwareOct 22, 2021

  • CVE-2016-0870
    21Monitor

    The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.

    MediumCVSS 5.3No exploitEPSS 1%

    trane · tracer scSep 18, 2016