← Back to browse · API

CVE-2021-38450

Severity
CRITICAL
CVSS
9.9
EPSS
0.00977
Risk score
39.94
CISA KEV
No
PoC
No
Published
2021-10-27
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-24902, GHSA-M3XR-5F4W-PX4W
Products
Trane:Tracer Concierge All <5.5 SP3, Trane:Tracer SC All <4.4 SP7, Trane:Tracer SC+ All <5.5 SP3
Sources
euvd EUVD-2021-24902

Description

The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

References