CVE-2021-20107
Last modified
CVE-2021-20107 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use the Bluetooth Low Energy (BLE) connectivity to read and write to many BLE characteristics on the device. Some of these control the flow of water, the sensitivity of the sensors, and information about maintenance.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sloan | Optima Eaf-100 Firmware | All versions |
| Sloan | Optima Eaf-150 Firmware | All versions |
| Sloan | Optima Eaf-200 Firmware | All versions |
| Sloan | Optima Eaf-225 Firmware | All versions |
| Sloan | Optima Eaf-250 Firmware | All versions |
| Sloan | Optima Eaf-275 Firmware | All versions |
| Sloan | Optima Eaf-350 Firmware | All versions |
| Sloan | Optima Eaf-700 Firmware | All versions |
| Sloan | Optima Eaf-750 Firmware | All versions |
| Sloan | Optima Ebf-187 Firmware | All versions |
| Sloan | Optima Ebf-415 Firmware | All versions |
| Sloan | Optima Ebf-425 Firmware | All versions |
| Sloan | Optima Ebf-550 Firmware | All versions |
| Sloan | Optima Ebf-615 Firmware | All versions |
| Sloan | Optima Ebf-650 Firmware | All versions |
| Sloan | Optima Ebf-665 Firmware | All versions |
| Sloan | Optima Ebf-750 Firmware | All versions |
| Sloan | Optima Ebf-775 Firmware | All versions |
| Sloan | Optima Ebf-85 Firmware | All versions |
| Sloan | Optima Ebf-850 Firmware | All versions |
| Sloan | Optima Etf-610 Firmware | All versions |
| Sloan | Optima Etf-600 Firmware | All versions |
| Sloan | Optima Etf-410 Firmware | All versions |
| Sloan | Optima Etf-420 Firmware | All versions |
| Sloan | Optima Etf-500 Firmware | All versions |
| Sloan | Optima Etf-660 Firmware | All versions |
| Sloan | Optima Etf-700 Firmware | All versions |
| Sloan | Optima Etf-770 Firmware | All versions |
| Sloan | Optima Etf-80 Firmware | All versions |
| Sloan | Optima Etf-800 Firmware | All versions |
| Sloan | Optima Etf-880 Firmware | All versions |
| Sloan | Basys Efx-300 Firmware | All versions |
| Sloan | Basys Efx-350 Firmware | All versions |
| Sloan | Basys Efx-375 Firmware | All versions |
| Sloan | Basys Efx-377 Firmware | All versions |
| Sloan | Basys Efx-380 Firmware | All versions |
| Sloan | Basys Efx-600 Firmware | All versions |
| Sloan | Basys Efx-650 Firmware | All versions |
| Sloan | Basys Efx-675 Firmware | All versions |
| Sloan | Basys Efx-677 Firmware | All versions |
| Sloan | Basys Efx-680 Firmware | All versions |
| Sloan | Basys Efx-200 Firmware | All versions |
| Sloan | Basys Efx-250 Firmware | All versions |
| Sloan | Basys Efx-275 Firmware | All versions |
| Sloan | Basys Efx-277 Firmware | All versions |
| Sloan | Basys Efx-280 Firmware | All versions |
| Sloan | Basys Efx-100 Firmware | All versions |
| Sloan | Basys Efx-150 Firmware | All versions |
| Sloan | Basys Efx-175 Firmware | All versions |
| Sloan | Basys Efx-177 Firmware | All versions |
Showing 50 of 71 affected configurations. See NVD for the full list.
References
- https://www.tenable.com/security/research/tra-2021-26-0Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-26-0Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20107?
How severe is CVE-2021-20107?
How do I fix CVE-2021-20107?
Are you affected by CVE-2021-20107?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
