CRITICAL🇵🇱 Wersja polska

CVE-2026-28252

CVSS 9.2v4.0pub. 2026-03-12upd. 2026-03-27

A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.

🤖 AI Analysis
How it works

The vulnerability results from the use of a weak or broken cryptographic algorithm in the device authentication process. An attacker can exploit weaknesses in this algorithm to effectively bypass identity verification without knowledge of valid credentials. As a result, unauthorized access with root privileges directly to the device's operating system is possible.

Impact

An attacker can gain full root-level access to the device, enabling control over the system, modification of its configuration, disruption of HVAC installation operations, or use of the device as an entry point for further OT/BMS network penetration.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references (https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-01). Additionally, it is recommended to isolate Trane Tracer devices from public networks, implement network segmentation, and monitor access to device management interfaces.

Who is affected

Trane Tracer SC, Trane Tracer SC+, and Trane Tracer Concierge — versions specified in manufacturer references (ICS advisory ICSA-26-071-01).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Trane Tracer Concierge

    APP
    Trane
    < 6.3.2310
  • Trane Tracer Sc

    HW
    Trane
    all versions
  • Trane Tracer Sc\+

    HW
    Trane
    all versions
  • Trane Tracer Sc Firmware

    OS
    Trane
    4.4≤ 4.4
  • Trane Tracer Sc\+ Firmware

    OS
    Trane
    < 6.3.2310
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2021-38450CRITICAL9.9PL ✓same product

Podatność code injection w kontrolerach Trane Tracer SC i Concierge

CVE-2026-28253HIGH8.7same product

A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concier...

CVE-2026-28255HIGH8.2same product

A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow...

CVE-2016-4526HIGH7.5same product

ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the packa...

CVE-2026-28256MEDIUM6.9same product

Podatność Use of Hard-coded, Security-relevant Constants w produktach Trane Tracer SC, Tracer SC+ i Tracer Con...