5.4
CVE-2021-20107
- EPSS 0.07%
- Veröffentlicht 30.06.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:45:56
- Quelle vulnreport@tenable.com
- CVE-Watchlists
- Unerledigt
There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use the Bluetooth Low Energy (BLE) connectivity to read and write to many BLE characteristics on the device. Some of these control the flow of water, the sensitivity of the sensors, and information about maintenance.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sloan ≫ Optima Eaf-100 Firmware Version-
Sloan ≫ Optima Eaf-150 Firmware Version-
Sloan ≫ Optima Eaf-200 Firmware Version-
Sloan ≫ Optima Eaf-225 Firmware Version-
Sloan ≫ Optima Eaf-250 Firmware Version-
Sloan ≫ Optima Eaf-275 Firmware Version-
Sloan ≫ Optima Eaf-350 Firmware Version-
Sloan ≫ Optima Eaf-700 Firmware Version-
Sloan ≫ Optima Eaf-750 Firmware Version-
Sloan ≫ Optima Ebf-187 Firmware Version-
Sloan ≫ Optima Ebf-415 Firmware Version-
Sloan ≫ Optima Ebf-425 Firmware Version-
Sloan ≫ Optima Ebf-550 Firmware Version-
Sloan ≫ Optima Ebf-615 Firmware Version-
Sloan ≫ Optima Ebf-650 Firmware Version-
Sloan ≫ Optima Ebf-665 Firmware Version-
Sloan ≫ Optima Ebf-750 Firmware Version-
Sloan ≫ Optima Ebf-775 Firmware Version-
Sloan ≫ Optima Ebf-85 Firmware Version-
Sloan ≫ Optima Ebf-850 Firmware Version-
Sloan ≫ Optima Etf-610 Firmware Version-
Sloan ≫ Optima Etf-600 Firmware Version-
Sloan ≫ Optima Etf-410 Firmware Version-
Sloan ≫ Optima Etf-420 Firmware Version-
Sloan ≫ Optima Etf-500 Firmware Version-
Sloan ≫ Optima Etf-660 Firmware Version-
Sloan ≫ Optima Etf-700 Firmware Version-
Sloan ≫ Optima Etf-770 Firmware Version-
Sloan ≫ Optima Etf-80 Firmware Version-
Sloan ≫ Optima Etf-800 Firmware Version-
Sloan ≫ Optima Etf-880 Firmware Version-
Sloan ≫ Basys Efx-300 Firmware Version-
Sloan ≫ Basys Efx-350 Firmware Version-
Sloan ≫ Basys Efx-375 Firmware Version-
Sloan ≫ Basys Efx-377 Firmware Version-
Sloan ≫ Basys Efx-380 Firmware Version-
Sloan ≫ Basys Efx-600 Firmware Version-
Sloan ≫ Basys Efx-650 Firmware Version-
Sloan ≫ Basys Efx-675 Firmware Version-
Sloan ≫ Basys Efx-677 Firmware Version-
Sloan ≫ Basys Efx-680 Firmware Version-
Sloan ≫ Basys Efx-200 Firmware Version-
Sloan ≫ Basys Efx-250 Firmware Version-
Sloan ≫ Basys Efx-275 Firmware Version-
Sloan ≫ Basys Efx-277 Firmware Version-
Sloan ≫ Basys Efx-280 Firmware Version-
Sloan ≫ Basys Efx-100 Firmware Version-
Sloan ≫ Basys Efx-150 Firmware Version-
Sloan ≫ Basys Efx-175 Firmware Version-
Sloan ≫ Basys Efx-177 Firmware Version-
Sloan ≫ Basys Efx-180 Firmware Version-
Sloan ≫ Basys Efx-800 Firmware Version-
Sloan ≫ Basys Efx-850 Firmware Version-
Sloan ≫ Solis 8111 Firmware Version-
Sloan ≫ Solis 8186 Firmware Version-
Sloan ≫ Solis Ress-c Firmware Version-
Sloan ≫ Solis Ress-u Firmware Version-
Sloan ≫ Solis 8152 Firmware Version-
Sloan ≫ Solis 8195 Firmware Version-
Sloan ≫ Solis 8115 Firmware Version-
Sloan ≫ Solis 8110 Firmware Version-
Sloan ≫ Solis 8180 Firmware Version-
Sloan ≫ Solis 8113 Firmware Version-
Sloan ≫ Solis 8137 Firmware Version-
Sloan ≫ Solis Bpw 8000 Firmware Version-
Sloan ≫ Solis 8116 Firmware Version-
Sloan ≫ Solis 8111 Bt Firmware Version-
Sloan ≫ Solis 8153 Firmware Version-
Sloan ≫ Solis 8186 Bt Firmware Version-
Sloan ≫ Solis Ress-c Bt Firmware Version-
Sloan ≫ Solis Ress-u Bt Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.226 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
| nvd@nist.gov | 4.8 | 6.5 | 4.9 |
AV:A/AC:L/Au:N/C:P/I:P/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.