The web server in Trane Tracer SC 4.2.1134 and previous versions allows remote malicious users to read sensitive configuration files via a direct request.
trane tracer sc