VendorsTranetracer_scany version
Vulnerabilities

Trane Tracer SC any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-38450
Trane Tracer Code Injection
Published 2021-10-27 · Modified
9.9EPSS 0.010
CVE-2026-28255
Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
Published 2026-03-12 · Analyzed
9.8EPSS 0.005
CVE-2026-28256
Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
Published 2026-03-12 · Analyzed
9.8EPSS 0.004
CVE-2026-28252
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
Published 2026-03-12 · Analyzed
9.8EPSS 0.003
CVE-2026-28253
Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
Published 2026-03-12 · Analyzed
8.7EPSS 0.005
CVE-2026-28254
Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
Published 2026-03-12 · Analyzed
7.5EPSS 0.004
CVE-2016-4526
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.
Published 2016-09-19 · Modified
7.5EPSS 0.003
CVE-2021-42534
Trane Building Automation Controllers Cross-site Scripting
Published 2021-10-22 · Modified
6.3EPSS 0.006
CVE-2016-0870
The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.
Published 2016-09-19 · Modified
5.3EPSS 0.012