Turning Up the Heat: Hacking Trane HVAC Controllers
ID: a1a5f1b4-64be-5650-b316-b2d32634d2e3
STIX ID: report--a1a5f1b4-64be-5650-b316-b2d32634d2e3
Feed Name: Claroty Team82
Team82 identified a chain of critical vulnerabilities in the Trane Tracer SC+ HVAC controller (affecting versions up to v6.2) that enable unauthenticated root SSH remote code execution via a deterministic PAM challenge-response bypass, a pre-auth HTTP/BACnet memory-allocation denial-of-service, multiple unauthenticated API routes exposing sensitive device and network data, and the presence of hardcoded global credentials and cryptographic keys; these issues could allow remote attackers to fully control building management systems and disrupt data-center cooling — Trane released v6.3 (Mar 1, 2026) as the remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
