Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:NDefault status
unaffected
Any version before v4.4 SP7
affected
Default status
unaffected
Any version before v6.3.2310
affected
Default status
unaffected
Any version before v6.3.2310
affected
Description
A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
Problem types
Product status
Any version before v4.4 SP7
Any version before v6.3.2310
Any version before v6.3.2310
Credits
Noam Moshe of Claroty reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-071-01