This page lists publicly disclosed CVE vulnerabilities affecting trane tracer_concierge (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-28256 | A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts. | [email protected] | 6.9 | 0.05% | 2026-03-12 | 2026-03-27 |
| CVE-2026-28255 | A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts. | [email protected] | 8.2 | 0.05% | 2026-03-12 | 2026-03-27 |
| CVE-2026-28254 | A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs. | [email protected] | 6.9 | 0.04% | 2026-03-12 | 2026-03-27 |
| CVE-2026-28253 | A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition | [email protected] | 8.7 | 0.05% | 2026-03-12 | 2026-03-27 |
| CVE-2026-28252 | A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device. | [email protected] | 9.2 | 0.04% | 2026-03-12 | 2026-03-27 |
| CVE-2021-38450 | The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software. | [email protected] | 9.9 | 0.28% | 2021-10-27 | 2024-11-21 |