Trane Tracer SC Products Hard-Coded Constants Vulnerability Allowing Account Takeover

Vulnerability

A vulnerability allowing the use of hard-coded, security-relevant constants has been identified in Trane Tracer SC, Tracer SC+, and Tracer Concierge. This vulnerability could enable an attacker to disclose sensitive information and take over accounts.

Impact

Exploitation of this vulnerability could lead to the disclosure of sensitive information and unauthorized account access.

Added: Mar 12, 2026, 6:24 PM
Updated: Mar 12, 2026, 6:24 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
5.0
exploitability
7.0
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.