CVE Database
/

CVE-2015-2868

Back to search

CVE-2015-2868

Published: Jan 6, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II device can send an overly long REG request that can overflow a fixed size stack buffer, resulting in arbitrary code execution.

VendorProductVersions

Trane

ComfortLink II SCC firmware

affected
2.0.2

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now