Trane Tracer SC Products Authentication Bypass Vulnerability Allowing Root Access

Vulnerability

A vulnerability allowing authentication bypass and root-level access has been identified in Trane Tracer SC, Tracer SC+, and Tracer Concierge. This issue arises from the use of a broken or risky cryptographic algorithm, which could be exploited by an attacker to gain unauthorized access to the device.

Impact

Exploitation of this vulnerability could lead to unauthorized authentication bypass and root-level access on the affected device.

Added: Mar 12, 2026, 6:26 PM
Updated: Mar 12, 2026, 6:26 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
7.0
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.