Записи Trane
13 опубликованных записей вендора trane.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-798 Use of Hard-coded Credentials2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-427 Uncontrolled Search Path Element1
- CWE-547 Use of Hard-coded, Security-relevant Constants1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2015-2868Эксплойта нет | An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service.trane · comfortlink ii firmware · CWE-119 | Критическая9,8 | — | 6,8 % | 6 янв. 2017 г. |
40В плане | CVE-2015-2867Эксплойта нет | A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.trane · comfortlink ii firmware · CWE-798 | Критическая9,8 | — | 4,9 % | 6 янв. 2017 г. |
36Наблюдать | CVE-2026-28252Эксплойта нет | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc firmware · CWE-327 | Критическая9,2 | — | 0,3 % | 12 мар. 2026 г. |
35Наблюдать | CVE-2021-38450Эксплойта нет | Trane Tracer Code Injectiontrane · tracer concierge · CWE-94 | Высокая8,8 | — | 1,0 % | 26 окт. 2021 г. |
34Наблюдать | CVE-2026-28253Эксплойта нет | Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc firmware · CWE-789 | Высокая8,7 | — | 0,5 % | 12 мар. 2026 г. |
32Наблюдать | CVE-2026-28255Эксплойта нет | Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc firmware · CWE-798 | Высокая8,2 | — | 0,5 % | 12 мар. 2026 г. |
30Наблюдать | CVE-2016-4526Эксплойта нет | ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.trane · tracer sc · CWE-427 | Высокая7,5 | — | 0,3 % | 18 сент. 2016 г. |
30Наблюдать | CVE-2021-38448Эксплойта нет | Trane Symbio Improper Control of Generation of Codetrane · symbio 700 · CWE-94 | Высокая7,6 | — | 0,3 % | 22 нояб. 2021 г. |
27Наблюдать | CVE-2023-4212Эксплойта нет | Trane Thermostats Injectiontrane · xl824 firmware · CWE-74 | Средняя6,8 | — | 1,3 % | 22 авг. 2023 г. |
27Наблюдать | CVE-2026-28256Эксплойта нет | Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc\+ firmware · CWE-547 | Средняя6,9 | — | 0,4 % | 12 мар. 2026 г. |
27Наблюдать | CVE-2026-28254Эксплойта нет | Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Conciergetrane · tracer sc firmware · CWE-862 | Средняя6,9 | — | 0,4 % | 12 мар. 2026 г. |
24Наблюдать | CVE-2021-42534Эксплойта нет | Trane Building Automation Controllers Cross-site Scriptingtrane · tracer sc firmware · CWE-79 | Средняя6,1 | — | 0,6 % | 22 окт. 2021 г. |
21Наблюдать | CVE-2016-0870Эксплойта нет | The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.trane · tracer sc · CWE-200 | Средняя5,3 | — | 1,2 % | 18 сент. 2016 г. |
- CVE-2015-286841В плане
An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %trane · comfortlink ii firmware6 янв. 2017 г.
- CVE-2015-286740В плане
A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %trane · comfortlink ii firmware6 янв. 2017 г.
- CVE-2026-2825236Наблюдать
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %trane · tracer sc firmware12 мар. 2026 г.
- CVE-2021-3845035Наблюдать
Trane Tracer Code Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %trane · tracer concierge26 окт. 2021 г.
- CVE-2026-2825334Наблюдать
Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %trane · tracer sc firmware12 мар. 2026 г.
- CVE-2026-2825532Наблюдать
Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %trane · tracer sc firmware12 мар. 2026 г.
- CVE-2016-452630Наблюдать
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %trane · tracer sc18 сент. 2016 г.
- CVE-2021-3844830Наблюдать
Trane Symbio Improper Control of Generation of Code
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %trane · symbio 70022 нояб. 2021 г.
- CVE-2023-421227Наблюдать
Trane Thermostats Injection
СредняяCVSS 6,8Эксплойта нетEPSS 1 %trane · xl824 firmware22 авг. 2023 г.
- CVE-2026-2825627Наблюдать
Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
СредняяCVSS 6,9Эксплойта нетEPSS 0 %trane · tracer sc\+ firmware12 мар. 2026 г.
- CVE-2026-2825427Наблюдать
Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
СредняяCVSS 6,9Эксплойта нетEPSS 0 %trane · tracer sc firmware12 мар. 2026 г.
- CVE-2021-4253424Наблюдать
Trane Building Automation Controllers Cross-site Scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %trane · tracer sc firmware22 окт. 2021 г.
- CVE-2016-087021Наблюдать
The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %trane · tracer sc18 сент. 2016 г.