CVE-2026-28253

A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:trane:tracer_sc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack1:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack2:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack3:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack4:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack5:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack6:*:*:*:*:*:*
cpe:2.3:h:trane:tracer_sc:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:trane:tracer_sc\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:trane:tracer_sc\+:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:trane:tracer_concierge:*:*:*:*:*:*:*:*

History

27 Mar 2026, 16:24

Type Values Removed Values Added
First Time Trane tracer Sc\+ Firmware
Trane
Trane tracer Sc Firmware
Trane tracer Concierge
Trane tracer Sc
Trane tracer Sc\+
CPE cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack5:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack3:*:*:*:*:*:*
cpe:2.3:h:trane:tracer_sc:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack2:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack1:*:*:*:*:*:*
cpe:2.3:a:trane:tracer_concierge:*:*:*:*:*:*:*:*
cpe:2.3:h:trane:tracer_sc\+:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack4:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack6:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) Una vulnerabilidad de Asignación de Memoria con Valor de Tamaño Excesivo en Trane Tracer SC, Tracer SC+ y Tracer Concierge podría permitir a un atacante no autenticado causar una condición de denegación de servicio.
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 - Third Party Advisory, US Government Resource

12 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 18:16

Updated : 2026-03-27 16:24


NVD link : CVE-2026-28253

Mitre link : CVE-2026-28253

CVE.ORG link : CVE-2026-28253


JSON object : View

Products Affected

trane

  • tracer_sc\+_firmware
  • tracer_sc\+
  • tracer_sc_firmware
  • tracer_sc
  • tracer_concierge
CWE
CWE-789

Memory Allocation with Excessive Size Value