CVE-2021-20107
Last modified
CVE-2021-20107 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use the Bluetooth Low Energy (BLE) connectivity to read and write to many BLE characteristics on the device. Some of these control the flow of water, the sensitivity of the sensors, and information about maintenance.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sloan | Optima Eaf-100 Firmware | All versions |
| Sloan | Optima Eaf-150 Firmware | All versions |
| Sloan | Optima Eaf-200 Firmware | All versions |
| Sloan | Optima Eaf-225 Firmware | All versions |
| Sloan | Optima Eaf-250 Firmware | All versions |
| Sloan | Optima Eaf-275 Firmware | All versions |
| Sloan | Optima Eaf-350 Firmware | All versions |
| Sloan | Optima Eaf-700 Firmware | All versions |
| Sloan | Optima Eaf-750 Firmware | All versions |
| Sloan | Optima Ebf-187 Firmware | All versions |
| Sloan | Optima Ebf-415 Firmware | All versions |
| Sloan | Optima Ebf-425 Firmware | All versions |
| Sloan | Optima Ebf-550 Firmware | All versions |
| Sloan | Optima Ebf-615 Firmware | All versions |
| Sloan | Optima Ebf-650 Firmware | All versions |
| Sloan | Optima Ebf-665 Firmware | All versions |
| Sloan | Optima Ebf-750 Firmware | All versions |
| Sloan | Optima Ebf-775 Firmware | All versions |
| Sloan | Optima Ebf-85 Firmware | All versions |
| Sloan | Optima Ebf-850 Firmware | All versions |
| Sloan | Optima Etf-610 Firmware | All versions |
| Sloan | Optima Etf-600 Firmware | All versions |
| Sloan | Optima Etf-410 Firmware | All versions |
| Sloan | Optima Etf-420 Firmware | All versions |
| Sloan | Optima Etf-500 Firmware | All versions |
| Sloan | Optima Etf-660 Firmware | All versions |
| Sloan | Optima Etf-700 Firmware | All versions |
| Sloan | Optima Etf-770 Firmware | All versions |
| Sloan | Optima Etf-80 Firmware | All versions |
| Sloan | Optima Etf-800 Firmware | All versions |
| Sloan | Optima Etf-880 Firmware | All versions |
| Sloan | Basys Efx-300 Firmware | All versions |
| Sloan | Basys Efx-350 Firmware | All versions |
| Sloan | Basys Efx-375 Firmware | All versions |
| Sloan | Basys Efx-377 Firmware | All versions |
| Sloan | Basys Efx-380 Firmware | All versions |
| Sloan | Basys Efx-600 Firmware | All versions |
| Sloan | Basys Efx-650 Firmware | All versions |
| Sloan | Basys Efx-675 Firmware | All versions |
| Sloan | Basys Efx-677 Firmware | All versions |
| Sloan | Basys Efx-680 Firmware | All versions |
| Sloan | Basys Efx-200 Firmware | All versions |
| Sloan | Basys Efx-250 Firmware | All versions |
| Sloan | Basys Efx-275 Firmware | All versions |
| Sloan | Basys Efx-277 Firmware | All versions |
| Sloan | Basys Efx-280 Firmware | All versions |
| Sloan | Basys Efx-100 Firmware | All versions |
| Sloan | Basys Efx-150 Firmware | All versions |
| Sloan | Basys Efx-175 Firmware | All versions |
| Sloan | Basys Efx-177 Firmware | All versions |
Showing 50 of 71 affected configurations. See NVD for the full list.
References
- https://www.tenable.com/security/research/tra-2021-26-0Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-26-0Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20107?
How severe is CVE-2021-20107?
How do I fix CVE-2021-20107?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-20101Machform prior to version 16 is vulnerable to HTTP host head…6.1
- CVE-2021-20102Machform prior to version 16 is vulnerable to cross-site req…8.8
- CVE-2021-20103Machform prior to version 16 is vulnerable to stored cross-s…6.1
- CVE-2021-20104Machform prior to version 16 is vulnerable to unauthenticate…8.1
- CVE-2021-20105Machform prior to version 16 is vulnerable to an open redire…6.1
- CVE-2021-20106Nessus Agent versions 8.2.5 and earlier were found to contai…6.5
- CVE-2021-20108Manage Engine Asset Explorer Agent 1.0.34 listens on port 90…7.5
- CVE-2021-20109Due to the Asset Explorer agent not validating HTTPS certifi…7.5
- CVE-2021-2011Vulnerability in the MySQL Client product of Oracle MySQL (c…5.9
- CVE-2021-20110Due to Manage Engine Asset Explorer Agent 1.0.34 not validat…9.8
- CVE-2021-20111A stored cross-site scripting vulnerability exists in TCExam…5.4
- CVE-2021-20112A stored cross-site scripting vulnerability exists in TCExam…5.4
Are you affected by CVE-2021-20107?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
