Description
There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use the Bluetooth Low Energy (BLE) connectivity to read and write to many BLE characteristics on the device. Some of these control the flow of water, the sensitivity of the sensors, and information about maintenance.
Published: 2021-06-30
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-7564 There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use the Bluetooth Low Energy (BLE) connectivity to read and write to many BLE characteristics on the device. Some of these control the flow of water, the sensitivity of the sensors, and information about maintenance.
History

No history.

Subscriptions

Sloan Basys Efx-100 Basys Efx-100 Firmware Basys Efx-150 Basys Efx-150 Firmware Basys Efx-175 Basys Efx-175 Firmware Basys Efx-177 Basys Efx-177 Firmware Basys Efx-180 Basys Efx-180 Firmware Basys Efx-200 Basys Efx-200 Firmware Basys Efx-250 Basys Efx-250 Firmware Basys Efx-275 Basys Efx-275 Firmware Basys Efx-277 Basys Efx-277 Firmware Basys Efx-280 Basys Efx-280 Firmware Basys Efx-300 Basys Efx-300 Firmware Basys Efx-350 Basys Efx-350 Firmware Basys Efx-375 Basys Efx-375 Firmware Basys Efx-377 Basys Efx-377 Firmware Basys Efx-380 Basys Efx-380 Firmware Basys Efx-600 Basys Efx-600 Firmware Basys Efx-650 Basys Efx-650 Firmware Basys Efx-675 Basys Efx-675 Firmware Basys Efx-677 Basys Efx-677 Firmware Basys Efx-680 Basys Efx-680 Firmware Basys Efx-800 Basys Efx-800 Firmware Basys Efx-850 Basys Efx-850 Firmware Optima Eaf-100 Optima Eaf-100 Firmware Optima Eaf-150 Optima Eaf-150 Firmware Optima Eaf-200 Optima Eaf-200 Firmware Optima Eaf-225 Optima Eaf-225 Firmware Optima Eaf-250 Optima Eaf-250 Firmware Optima Eaf-275 Optima Eaf-275 Firmware Optima Eaf-350 Optima Eaf-350 Firmware Optima Eaf-700 Optima Eaf-700 Firmware Optima Eaf-750 Optima Eaf-750 Firmware Optima Ebf-187 Optima Ebf-187 Firmware Optima Ebf-415 Optima Ebf-415 Firmware Optima Ebf-425 Optima Ebf-425 Firmware Optima Ebf-550 Optima Ebf-550 Firmware Optima Ebf-615 Optima Ebf-615 Firmware Optima Ebf-650 Optima Ebf-650 Firmware Optima Ebf-665 Optima Ebf-665 Firmware Optima Ebf-750 Optima Ebf-750 Firmware Optima Ebf-775 Optima Ebf-775 Firmware Optima Ebf-85 Optima Ebf-850 Optima Ebf-850 Firmware Optima Ebf-85 Firmware Optima Etf-410 Optima Etf-410 Firmware Optima Etf-420 Optima Etf-420 Firmware Optima Etf-500 Optima Etf-500 Firmware Optima Etf-600 Optima Etf-600 Firmware Optima Etf-610 Optima Etf-610 Firmware Optima Etf-660 Optima Etf-660 Firmware Optima Etf-700 Optima Etf-700 Firmware Optima Etf-770 Optima Etf-770 Firmware Optima Etf-80 Optima Etf-800 Optima Etf-800 Firmware Optima Etf-80 Firmware Optima Etf-880 Optima Etf-880 Firmware Solis 8110 Solis 8110 Firmware Solis 8111 Solis 8111 Bt Solis 8111 Bt Firmware Solis 8111 Firmware Solis 8113 Solis 8113 Firmware Solis 8115 Solis 8115 Firmware Solis 8116 Solis 8116 Firmware Solis 8137 Solis 8137 Firmware Solis 8152 Solis 8152 Firmware Solis 8153 Solis 8153 Firmware Solis 8180 Solis 8180 Firmware Solis 8186 Solis 8186 Bt Solis 8186 Bt Firmware Solis 8186 Firmware Solis 8195 Solis 8195 Firmware Solis Bpw 8000 Solis Bpw 8000 Firmware Solis Ress-c Solis Ress-c Bt Solis Ress-c Bt Firmware Solis Ress-c Firmware Solis Ress-u Solis Ress-u Bt Solis Ress-u Bt Firmware Solis Ress-u Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-03T17:30:08.193Z

Reserved: 2020-12-17T00:00:00.000Z

Link: CVE-2021-20107

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-30T14:15:08.487

Modified: 2024-11-21T05:45:56.130

Link: CVE-2021-20107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses