Description
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.
Problem types
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Product status
Any version before v4.4 SP7
Any version before v6.3.2310
Any version before v6.3.2310
Credits
Noam Moshe of Claroty reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-071-01