CVE-2026-28255

A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:trane:tracer_sc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack1:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack2:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack3:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack4:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack5:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack6:*:*:*:*:*:*
cpe:2.3:h:trane:tracer_sc:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:trane:tracer_sc\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:trane:tracer_sc\+:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:trane:tracer_concierge:*:*:*:*:*:*:*:*

History

27 Mar 2026, 16:25

Type Values Removed Values Added
CPE cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack5:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack3:*:*:*:*:*:*
cpe:2.3:h:trane:tracer_sc:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack2:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack1:*:*:*:*:*:*
cpe:2.3:a:trane:tracer_concierge:*:*:*:*:*:*:*:*
cpe:2.3:h:trane:tracer_sc\+:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack4:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc\+_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack6:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Una vulnerabilidad de uso de credenciales codificadas de forma rígida en Trane Tracer SC, Tracer SC+ y Tracer Concierge podría permitir a un atacante divulgar información sensible y tomar el control de cuentas.
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 - Third Party Advisory, US Government Resource
First Time Trane tracer Sc\+ Firmware
Trane
Trane tracer Sc Firmware
Trane tracer Concierge
Trane tracer Sc
Trane tracer Sc\+

12 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 18:16

Updated : 2026-03-27 16:25


NVD link : CVE-2026-28255

Mitre link : CVE-2026-28255

CVE.ORG link : CVE-2026-28255


JSON object : View

Products Affected

trane

  • tracer_sc\+_firmware
  • tracer_sc\+
  • tracer_sc_firmware
  • tracer_sc
  • tracer_concierge
CWE
CWE-798

Use of Hard-coded Credentials