Trane records
13 published records for vendor trane.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-798 Use of Hard-coded Credentials2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-427 Uncontrolled Search Path Element1
- CWE-547 Use of Hard-coded, Security-relevant Constants1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2015-2868No exploit | An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service.trane · comfortlink ii firmware · CWE-119 | Critical9.8 | — | 7.0% | Jan 6, 2017 |
40Plan | CVE-2015-2867No exploit | A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.trane · comfortlink ii firmware · CWE-798 | Critical9.8 | — | 5.0% | Jan 6, 2017 |
36Monitor | CVE-2026-28252No exploit | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc firmware · CWE-327 | Critical9.2 | — | 0.4% | Mar 12, 2026 |
35Monitor | CVE-2021-38450No exploit | Trane Tracer Code Injectiontrane · tracer concierge · CWE-94 | High8.8 | — | 1.0% | Oct 26, 2021 |
34Monitor | CVE-2026-28253No exploit | Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc firmware · CWE-789 | High8.7 | — | 0.5% | Mar 12, 2026 |
32Monitor | CVE-2026-28255No exploit | Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc firmware · CWE-798 | High8.2 | — | 0.5% | Mar 12, 2026 |
30Monitor | CVE-2016-4526No exploit | ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.trane · tracer sc · CWE-427 | High7.5 | — | 0.3% | Sep 18, 2016 |
30Monitor | CVE-2021-38448No exploit | Trane Symbio Improper Control of Generation of Codetrane · symbio 700 · CWE-94 | High7.6 | — | 0.3% | Nov 22, 2021 |
27Monitor | CVE-2023-4212No exploit | Trane Thermostats Injectiontrane · xl824 firmware · CWE-74 | Medium6.8 | — | 1.3% | Aug 22, 2023 |
27Monitor | CVE-2026-28256No exploit | Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc\+ firmware · CWE-547 | Medium6.9 | — | 0.5% | Mar 12, 2026 |
27Monitor | CVE-2026-28254No exploit | Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc firmware · CWE-862 | Medium6.9 | — | 0.4% | Mar 12, 2026 |
24Monitor | CVE-2021-42534No exploit | Trane Building Automation Controllers Cross-site Scriptingtrane · tracer sc firmware · CWE-79 | Medium6.1 | — | 0.6% | Oct 22, 2021 |
21Monitor | CVE-2016-0870No exploit | The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.trane · tracer sc · CWE-200 | Medium5.3 | — | 1.2% | Sep 18, 2016 |
- CVE-2015-286841Plan
An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service.
CriticalCVSS 9.8No exploitEPSS 7%trane · comfortlink ii firmwareJan 6, 2017
- CVE-2015-286740Plan
A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.
CriticalCVSS 9.8No exploitEPSS 5%trane · comfortlink ii firmwareJan 6, 2017
- CVE-2026-2825236Monitor
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
CriticalCVSS 9.2No exploitEPSS 0%trane · tracer sc firmwareMar 12, 2026
- CVE-2021-3845035Monitor
Trane Tracer Code Injection
HighCVSS 8.8No exploitEPSS 1%trane · tracer conciergeOct 26, 2021
- CVE-2026-2825334Monitor
Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
HighCVSS 8.7No exploitEPSS 1%trane · tracer sc firmwareMar 12, 2026
- CVE-2026-2825532Monitor
Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
HighCVSS 8.2No exploitEPSS 0%trane · tracer sc firmwareMar 12, 2026
- CVE-2016-452630Monitor
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.
HighCVSS 7.5No exploitEPSS 0%trane · tracer scSep 18, 2016
- CVE-2021-3844830Monitor
Trane Symbio Improper Control of Generation of Code
HighCVSS 7.6No exploitEPSS 0%trane · symbio 700Nov 22, 2021
- CVE-2023-421227Monitor
Trane Thermostats Injection
MediumCVSS 6.8No exploitEPSS 1%trane · xl824 firmwareAug 22, 2023
- CVE-2026-2825627Monitor
Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
MediumCVSS 6.9No exploitEPSS 0%trane · tracer sc\+ firmwareMar 12, 2026
- CVE-2026-2825427Monitor
Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
MediumCVSS 6.9No exploitEPSS 0%trane · tracer sc firmwareMar 12, 2026
- CVE-2021-4253424Monitor
Trane Building Automation Controllers Cross-site Scripting
MediumCVSS 6.1No exploitEPSS 1%trane · tracer sc firmwareOct 22, 2021
- CVE-2016-087021Monitor
The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.
MediumCVSS 5.3No exploitEPSS 1%trane · tracer scSep 18, 2016