?A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.
References
Link | Resource |
---|---|
https://https://www.cisa.gov/news-events/ics-advisories/icsa-23-234-02 | Broken Link |
https://hub.tranetechnologies.com/docs/DOC-216377 | Permissions Required |
https://www.trane.com/commercial/north-america/us/en/contact-us/locate-sales-offices.html | Product |
https://www.cisa.gov/news-events/ics-advisories/icsa-23-234-02 | Third Party Advisory |
https://https://www.cisa.gov/news-events/ics-advisories/icsa-23-234-02 | Broken Link |
https://hub.tranetechnologies.com/docs/DOC-216377 | Permissions Required |
https://www.trane.com/commercial/north-america/us/en/contact-us/locate-sales-offices.html | Product |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 08:34
Type | Values Removed | Values Added |
---|---|---|
References | () https://https://www.cisa.gov/news-events/ics-advisories/icsa-23-234-02 - Broken Link | |
References | () https://hub.tranetechnologies.com/docs/DOC-216377 - Permissions Required | |
References | () https://www.trane.com/commercial/north-america/us/en/contact-us/locate-sales-offices.html - Product |
29 Aug 2023, 14:27
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
CWE | CWE-77 | |
CPE | cpe:2.3:h:trane:xl1050:-:*:*:*:*:*:*:* cpe:2.3:o:trane:xl824_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:trane:xl1050_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:trane:xl850:-:*:*:*:*:*:*:* cpe:2.3:o:trane:pivot_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:trane:xl824:-:*:*:*:*:*:*:* cpe:2.3:o:trane:xl850_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:trane:pivot:-:*:*:*:*:*:*:* |
|
References |
|
|
References | (MISC) https://hub.tranetechnologies.com/docs/DOC-216377 - Permissions Required | |
References | (MISC) https://www.trane.com/commercial/north-america/us/en/contact-us/locate-sales-offices.html - Product | |
References | (MISC) https://https://www.cisa.gov/news-events/ics-advisories/icsa-23-234-02 - Broken Link | |
First Time |
Trane
Trane xl1050 Firmware Trane xl850 Trane xl1050 Trane pivot Firmware Trane pivot Trane xl850 Firmware Trane xl824 Trane xl824 Firmware |
22 Aug 2023, 20:10
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-22 19:16
Updated : 2024-11-21 08:34
NVD link : CVE-2023-4212
Mitre link : CVE-2023-4212
CVE.ORG link : CVE-2023-4212
JSON object : View
Products Affected
trane
- xl824_firmware
- xl850
- xl1050
- pivot
- xl1050_firmware
- xl850_firmware
- pivot_firmware
- xl824