ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.
CVSS Vector
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HTrane Tracer Sc
APPTrane≤ 4.2.1134
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2026-28252CRITICAL9.2PL ✓same product
Podatność kryptograficzna w Trane Tracer SC umożliwiająca pominięcie uwierzytelnienia
CVE-2021-38450CRITICAL9.9PL ✓same product
Podatność code injection w kontrolerach Trane Tracer SC i Concierge
CVE-2026-28253HIGH8.7same product
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concier...
CVE-2026-28255HIGH8.2same product
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow...
CVE-2026-28256MEDIUM6.9same product
Podatność Use of Hard-coded, Security-relevant Constants w produktach Trane Tracer SC, Tracer SC+ i Tracer Con...