ID

VAR-202106-0570


CVE

CVE-2021-20107


TITLE

plural  Sloan SmartFaucet  Product authentication vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2021-008919

DESCRIPTION

There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use the Bluetooth Low Energy (BLE) connectivity to read and write to many BLE characteristics on the device. Some of these control the flow of water, the sensitivity of the sensors, and information about maintenance. plural Sloan SmartFaucet The product contains an authentication vulnerability.Information may be obtained and information may be tampered with

Trust: 1.71

sources: NVD: CVE-2021-20107 // JVNDB: JVNDB-2021-008919 // VULMON: CVE-2021-20107

IOT TAXONOMY

category:['home & office device']sub_category:smart faucet

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:sloanmodel:optima ebf-550scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-675scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima ebf-850scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8137scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-610scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima ebf-775scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8110scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-375scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8186scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-100scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-850scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8180scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-500scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis ress-cscope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-800scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-300scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-150scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8153scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-677scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima eaf-350scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis ress-c btscope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima ebf-650scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima ebf-85scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima eaf-100scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis bpw 8000scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8111 btscope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-420scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima ebf-425scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-177scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima ebf-665scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8115scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-660scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-277scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima eaf-200scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima eaf-275scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-880scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima eaf-225scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima ebf-750scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-700scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima eaf-700scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-80scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-350scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-600scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima ebf-415scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-175scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima eaf-150scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis ress-uscope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8195scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8113scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-380scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima eaf-750scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima ebf-187scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima eaf-250scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-770scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-600scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-200scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-800scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8186 btscope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8116scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-280scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-250scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-377scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis ress-u btscope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8152scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-650scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima etf-410scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-680scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-275scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:optima ebf-615scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:basys efx-180scope:eqversion: -

Trust: 1.0

vendor:sloanmodel:solis 8111scope:eqversion: -

Trust: 1.0

vendor:sloan valvemodel:optima eaf 750scope: - version: -

Trust: 0.8

vendor:sloan valvemodel:optima eaf 100scope: - version: -

Trust: 0.8

vendor:sloan valvemodel:optima eaf 225scope: - version: -

Trust: 0.8

vendor:sloan valvemodel:optima ebf 187scope: - version: -

Trust: 0.8

vendor:sloan valvemodel:optima eaf 250scope: - version: -

Trust: 0.8

vendor:sloan valvemodel:optima eaf 150scope: - version: -

Trust: 0.8

vendor:sloan valvemodel:optima eaf 350scope: - version: -

Trust: 0.8

vendor:sloan valvemodel:optima eaf 275scope: - version: -

Trust: 0.8

vendor:sloan valvemodel:optima eaf 200scope: - version: -

Trust: 0.8

vendor:sloan valvemodel:optima eaf 700scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-008919 // NVD: CVE-2021-20107

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-20107
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-20107
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202106-1973
value: MEDIUM

Trust: 0.6

VULMON: CVE-2021-20107
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-20107
severity: MEDIUM
baseScore: 4.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.5
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2021-20107
baseSeverity: MEDIUM
baseScore: 5.4
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.5
version: 3.1

Trust: 1.0

NVD: CVE-2021-20107
baseSeverity: MEDIUM
baseScore: 5.4
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2021-20107 // JVNDB: JVNDB-2021-008919 // CNNVD: CNNVD-202106-1973 // NVD: CVE-2021-20107

PROBLEMTYPE DATA

problemtype:CWE-306

Trust: 1.0

problemtype:Improper authentication (CWE-287) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-008919 // NVD: CVE-2021-20107

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202106-1973

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202106-1973

PATCH

title:Top Pageurl:https://www.sloan.com/

Trust: 0.8

title:Sloan SmartFaucets Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=155586

Trust: 0.6

sources: JVNDB: JVNDB-2021-008919 // CNNVD: CNNVD-202106-1973

EXTERNAL IDS

db:NVDid:CVE-2021-20107

Trust: 3.4

db:TENABLEid:TRA-2021-26

Trust: 2.5

db:JVNDBid:JVNDB-2021-008919

Trust: 0.8

db:CNNVDid:CNNVD-202106-1973

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULMONid:CVE-2021-20107

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2021-20107 // JVNDB: JVNDB-2021-008919 // CNNVD: CNNVD-202106-1973 // NVD: CVE-2021-20107

REFERENCES

url:https://www.tenable.com/security/research/tra-2021-26-0

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2021-20107

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2021-20107 // JVNDB: JVNDB-2021-008919 // CNNVD: CNNVD-202106-1973 // NVD: CVE-2021-20107

SOURCES

db:OTHERid: -
db:VULMONid:CVE-2021-20107
db:JVNDBid:JVNDB-2021-008919
db:CNNVDid:CNNVD-202106-1973
db:NVDid:CVE-2021-20107

LAST UPDATE DATE

2025-01-30T21:06:39.943000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-20107date:2021-07-08T00:00:00
db:JVNDBid:JVNDB-2021-008919date:2022-03-31T07:30:00
db:CNNVDid:CNNVD-202106-1973date:2022-06-30T00:00:00
db:NVDid:CVE-2021-20107date:2022-06-28T14:11:45.273

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-20107date:2021-06-30T00:00:00
db:JVNDBid:JVNDB-2021-008919date:2022-03-31T00:00:00
db:CNNVDid:CNNVD-202106-1973date:2021-06-30T00:00:00
db:NVDid:CVE-2021-20107date:2021-06-30T14:15:08.487