CVE-2026-28252
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.
| CWE | CWE-327 |
| Vendor | trane |
| Product | tracer sc |
| Published | Mar 12, 2026 |
| Last Updated | Mar 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for trane tracer sc
Be the first to know when new unknown vulnerabilities affecting trane tracer sc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Trane / Tracer SC
0 < v4.4 SP7
Trane / Tracer SC+
0 < v6.3.2310
Trane / Tracer Concierge
0 < v6.3.2310
References
Credits
Noam Moshe of Claroty reported these vulnerabilities to CISA.