ZeroHour

CVE-2023-4212

CVSS 3.1
6.8 medium
EPSS
1%p69
Published
()
Modified
Description

​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

Vendors
trane
Products
xl824 firmware, xl850 firmware, xl1050 firmware, pivot firmware
Weakness
CWE-74, CWE-77
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.