Back to Database
Status published
Critical
CVE-2015-2867
A design flaw in the Trane ComfortLink II SCC firmware...
Vulnerability Description
A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-2867
Credits & Attribution
No credits recorded in the NVD database.
References
More from Trane
View All →CVE-2021-42534
Trane Building Automation Controllers Cross-site Scripting
Medium
6.3
CVE-2021-38450
Trane Tracer Code Injection
Critical
9.9
CVE-2021-38448
Trane Symbio Improper Control of Generation of Code
High
7.5
CVE-2015-2868
An exploitable remote code execution vulnerability exists in the Trane...
Critical
9.8
Affected Vendor
Trane
View all reports →Affected Software
ComfortLink II SCC firmware
Vulnerable Versions:
2.0.2
Timeline
Official Publish:
January 6th, 2017
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.