Home

Description

A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

PUBLISHED Reserved 2026-02-25 | Published 2026-03-12 | Updated 2026-03-12 | Assigner icscert




MEDIUM: 6.9CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Problem types

CWE-547 Use of hard-coded, security-relevant constants

Product status

Default status
unaffected

Any version before v4.4 SP7
affected

Default status
unaffected

Any version before v6.3.2310
affected

Default status
unaffected

Any version before v6.3.2310
affected

Credits

Noam Moshe of Claroty reported these vulnerabilities to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-26-071-01 government-resource

cve.org (CVE-2026-28256)

nvd.nist.gov (CVE-2026-28256)

Download JSON