{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-24T22:06:56.187","vulnerabilities":[{"cve":{"id":"CVE-2015-2868","sourceIdentifier":"cret@cert.org","published":"2017-01-06T21:59:00.197","lastModified":"2026-06-17T00:24:53.647","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II device can send an overly long REG request that can overflow a fixed size stack buffer, resulting in arbitrary code execution."},{"lang":"es","value":"Existe una vulnerabilidad de ejecución remota de código explotable en el firmware de Trane ComfortLink II versión 2.0.2 en el servicio DSS. Un atacante que pueda conectarse al servicio DSS en el dispositivo Trane ComfortLink II puede enviar una solicitud REG excesivamente larga que puede desbordar un búfer en pila de tamaño fijo, resultando en la ejecución de código arbitrario.\""}],"affected":[{"source":"cret@cert.org","affectedData":[{"vendor":"Trane","product":"ComfortLink II SCC firmware","versions":[{"version":"2.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-119"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:trane:comfortlink_ii_firmware:2.0.2:*:*:*:*:*:*:*","matchCriteriaId":"25C2D7CF-A6C4-4D3E-9359-5879960ADC26"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/95118","source":"cret@cert.org"},{"url":"http://www.talosintelligence.com/reports/TALOS-2016-0027/","source":"cret@cert.org","tags":["Exploit","Technical Description","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/95118","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.talosintelligence.com/reports/TALOS-2016-0027/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Technical Description","Third Party Advisory"]}]}}]}