CVE-2026-28253 is a memory allocation vulnerability impacting Trane Tracer SC, Tracer SC+, and Tracer Concierge products. An unauthenticated attacker can remotely exploit this flaw with low complexity to cause a denial-of-service condition, earning it a CVSS score of 7.5 (HIGH). There is currently no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While not on CISA's Known Exploited Vulnerabilities catalog, it has been noted in a CISA alert, though community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.4CPE matchmatch criteria | cpe:2.3:o:trane:tracer_sc_firmware:*:*:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack1:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack2:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack3:*:*:*:*:*:* | ||
4.4CPE matchmatch criteria | cpe:2.3:o:trane:tracer_sc_firmware:4.4:service_pack4:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.