ICS/OT

Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers

Claroty researchers have analyzed the security of Vertiv UPS network cards and the Trane Tracer SC+ HVAC controller.

Data center cybersecurity

Researchers at cyber-physical systems security firm Claroty have uncovered multiple vulnerabilities in two widely deployed HVAC and UPS products used in data centers, demonstrating how attackers could exploit them to launch disruptive remote attacks.

The researchers targeted network cards designed to provide a network interface for uninterruptible power supply devices made by Vertiv.

“UPSs are heavily used in data centers to maintain operations in the event of a power outage; they also protect systems from power spikes and drops, and enable safe shutdowns,” Claroty noted.

The security firm’s researchers found that the Vertiv network cards, which provide a default web interface for UPS devices, are affected by two vulnerabilities: an authentication bypass flaw and a remote code execution vulnerability.

Chaining the two security holes can allow an attacker to remotely access the targeted UPS and execute arbitrary code, potentially causing significant operational disruptions.

“What makes [the vulnerabilities] especially concerning is the context: in large data centers, virtually all computing equipment relies on UPS devices to stay online during power issues,” Claroty explained. “Any weakness in those UPS communication modules can directly affect the machines they protect.”

Separately, Claroty researchers analyzed the Trane Tracer SC+ HVAC controller, which is widely used in data centers and other critical environments worldwide.

Advertisement. Scroll to continue reading.

They discovered several flaws, including authentication bypass, remote code execution, DoS, and sensitive information disclosure issues. 

“The vulnerabilities are highly exploitable and, if weaponized, could allow unauthenticated remote code execution (RCE) and extensive sensitive information disclosure. In practice, this could give an attacker complete control over a critical building management system from the outside,” Claroty said. 

“Data center servers generate enormous amounts of heat, and an HVAC failure is far more than a comfort issue. It can trigger thermal shutdowns, damage expensive hardware, cause major service disruptions, and lead to millions of dollars in losses,” the company noted.

Claroty reported its findings to Trane and Vertiv and worked with them to patch the vulnerabilities.

Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact

Related: Real-World ICS Security Tales From the Trenches

Related: Critical Vulnerability Exposes Industrial Robot Fleets to Hacking

Related Content

Vulnerabilities

Splunk patched an OS command injection in AI Toolkit, while Atlassian fixed dozens of flaws in third-party dependencies.

Network Security

Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root.

Vulnerabilities

Critical flaws in NGINX could allow remote, unauthenticated attackers to cause a restart and potentially execute arbitrary code.

ICS/OT

The industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products.

Vulnerabilities

Oracle has released its June 2026 Critical Security Patch Update to fix vulnerabilities in Communications, EBS, Enterprise Manager and other products.

Vulnerabilities

The browser updates address multiple memory safety bugs that could potentially lead to remote code execution.

Vulnerabilities

The flaws allow attackers to execute arbitrary PHP code and gain root privileges on shared hosting servers.

Vulnerabilities

SOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version