Back

CVE-2015-2868

CRITICAL

An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II device can send an overly long REG request that can overflow a fixed size stack buffer, resulting in arbitrary code execution.

Published: Jan 6, 2017 Modified: Jun 17, 2026
CWE-119

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
trane comfortlink_ii_firmware 2.0.2

GitHub Security Advisory GHSA-rggx-gpg5-f3h9

An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 6.84%

Top 7% most likely to be exploited

Threat Score 41.3 / 100

Data Sources

NVD EPSS GitHub