Home

Description

A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition

PUBLISHED Reserved 2026-02-25 | Published 2026-03-12 | Updated 2026-03-13 | Assigner icscert




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-789 Memory allocation with excessive size value

Product status

Default status
unaffected

Any version before v4.4 SP7
affected

Default status
unaffected

Any version before v6.3.2310
affected

Default status
unaffected

Any version before v6.3.2310
affected

Credits

Noam Moshe of Claroty reported these vulnerabilities to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 government-resource

cve.org (CVE-2026-28253)

nvd.nist.gov (CVE-2026-28253)

Download JSON