RULE(RULE ID:324058)

Rule General Information
Release Date: 2020-01-19
Rule Name: Trane Tracer SC Information Exposure Vulnerability (CVE-2016-0870)
Severity:
CVE ID:
Rule Protection Details
Description: The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux
Reference: SecurityFocusBID:92979
https://ics-cert.us-cert.gov/advisories/ICSA-16-259-03
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.trane.com/