NA

CVE-2023-4212

Published: 22/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 0

Vulnerability Summary

?A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an malicious user to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

Vulnerable Product Search on Vulmon Subscribe to Product

trane xl824_firmware

trane xl850_firmware

trane xl1050_firmware

trane pivot_firmware