Trane Tracer SC+ HVAC controller (up to v5.20.1362): vulnerability chain disclosed by Claroty Team82
5 CVEs, CVSS up to 8.1; fixed in v6.3observed
| Value kind | observed — Reported measurements, counts, and specifications keep the precision and scope stated by their source; an exact specification is not treated as a range. |
|---|---|
| Scope | Disclosed and patched; the chain gives an unauthenticated remote attacker control of the controller. Named data-center equipment, not generic BMS. |
| As of | 2026-06-09 |
| Source | Claroty Team82, "Turning Up the Heat: Hacking Trane HVAC Controllers", 2026-06-09; states CVE-2026-28252 (authentication bypass to RCE, CVSS 8.1), CVE-2026-28253 (pre-auth DoS, 7.5), CVE-2026-28254 (unauthenticated information disclosure, 5.8), CVE-2026-28255 (hardcoded credentials on disk, 6.8), CVE-2026-28256 (hard-coded security constants, 5.8) affecting Tracer SC+ up to v5.20.1362; Trane fix v6.3 released 2026-03-01. · Research post CVE table and remediation section. |
| Review | checking…review by 2027-03-08 · standard cadence |
| Recorded changes | none recorded |
| Claim id | p2b-11-10-trane-tracer-sc-cves |
Where the guide uses it
Not quoted in a chapter yet; it is kept in the curated register.
← Full numbers register — every date-stamped figure in the guide, with revision history.