5.4
CVSSv3

CVE-2021-20107

Published: 30/06/2021 Updated: 08/07/2021
CVSS v2 Base Score: 4.8 | Impact Score: 4.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 427
Vector: AV:A/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use the Bluetooth Low Energy (BLE) connectivity to read and write to many BLE characteristics on the device. Some of these control the flow of water, the sensitivity of the sensors, and information about maintenance.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sloan optima_eaf-100_firmware -

sloan optima_eaf-150_firmware -

sloan optima_eaf-200_firmware -

sloan optima_eaf-225_firmware -

sloan optima_eaf-250_firmware -

sloan optima_eaf-275_firmware -

sloan optima_eaf-350_firmware -

sloan optima_eaf-700_firmware -

sloan optima_eaf-750_firmware -

sloan optima_ebf-187_firmware -

sloan optima_ebf-415_firmware -

sloan optima_ebf-425_firmware -

sloan optima_ebf-550_firmware -

sloan optima_ebf-615_firmware -

sloan optima_ebf-650_firmware -

sloan optima_ebf-665_firmware -

sloan optima_ebf-750_firmware -

sloan optima_ebf-775_firmware -

sloan optima_ebf-85_firmware -

sloan optima_ebf-850_firmware -

sloan optima_etf-610_firmware -

sloan optima_etf-600_firmware -

sloan optima_etf-410_firmware -

sloan optima_etf-420_firmware -

sloan optima_etf-500_firmware -

sloan optima_etf-660_firmware -

sloan optima_etf-700_firmware -

sloan optima_etf-770_firmware -

sloan optima_etf-80_firmware -

sloan optima_etf-800_firmware -

sloan optima_etf-880_firmware -

sloan basys_efx-300_firmware -

sloan basys_efx-350_firmware -

sloan basys_efx-375_firmware -

sloan basys_efx-377_firmware -

sloan basys_efx-380_firmware -

sloan basys_efx-600_firmware -

sloan basys_efx-650_firmware -

sloan basys_efx-675_firmware -

sloan basys_efx-677_firmware -

sloan basys_efx-680_firmware -

sloan basys_efx-200_firmware -

sloan basys_efx-250_firmware -

sloan basys_efx-275_firmware -

sloan basys_efx-277_firmware -

sloan basys_efx-280_firmware -

sloan basys_efx-100_firmware -

sloan basys_efx-150_firmware -

sloan basys_efx-175_firmware -

sloan basys_efx-177_firmware -

sloan basys_efx-180_firmware -

sloan basys_efx-800_firmware -

sloan basys_efx-850_firmware -

sloan solis_8111_firmware -

sloan solis_8186_firmware -

sloan solis_ress-c_firmware -

sloan solis_ress-u_firmware -

sloan solis_8152_firmware -

sloan solis_8195_firmware -

sloan solis_8115_firmware -

sloan solis_8110_firmware -

sloan solis_8180_firmware -

sloan solis_8113_firmware -

sloan solis_8137_firmware -

sloan solis_bpw_8000_firmware -

sloan solis_8116_firmware -

sloan solis_8111_bt_firmware -

sloan solis_8153_firmware -

sloan solis_8186_bt_firmware -

sloan solis_ress-c_bt_firmware -

sloan solis_ress-u_bt_firmware -