A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.
The vulnerability results from the use of a weak or broken cryptographic algorithm in the device authentication process. An attacker can exploit weaknesses in this algorithm to effectively bypass identity verification without knowledge of valid credentials. As a result, unauthorized access with root privileges directly to the device's operating system is possible.
An attacker can gain full root-level access to the device, enabling control over the system, modification of its configuration, disruption of HVAC installation operations, or use of the device as an entry point for further OT/BMS network penetration.
Patches available from the manufacturer should be applied in accordance with the references (https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-01). Additionally, it is recommended to isolate Trane Tracer devices from public networks, implement network segmentation, and monitor access to device management interfaces.
Trane Tracer SC, Trane Tracer SC+, and Trane Tracer Concierge — versions specified in manufacturer references (ICS advisory ICSA-26-071-01).
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XTrane Tracer Concierge
APPTrane< 6.3.2310Trane Tracer Sc
HWTraneall versionsTrane Tracer Sc\+
HWTraneall versionsTrane Tracer Sc Firmware
OSTrane4.4≤ 4.4Trane Tracer Sc\+ Firmware
OSTrane< 6.3.2310
Related vulnerabilities
Podatność code injection w kontrolerach Trane Tracer SC i Concierge
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concier...
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow...
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the packa...
Podatność Use of Hard-coded, Security-relevant Constants w produktach Trane Tracer SC, Tracer SC+ i Tracer Con...