Home

Description

A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

PUBLISHED Reserved 2026-02-25 | Published 2026-03-12 | Updated 2026-03-12 | Assigner icscert




HIGH: 8.2CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Problem types

CWE-798 Use of Hard-coded Credentials

Product status

Default status
unaffected

Any version before v4.4 SP7
affected

Default status
unaffected

Any version before v6.3.2310
affected

Default status
unaffected

Any version before v6.3.2310
affected

Credits

Noam Moshe of Claroty reported these vulnerabilities to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 government-resource

cve.org (CVE-2026-28255)

nvd.nist.gov (CVE-2026-28255)

Download JSON