CVE-2013-4866
low
CVSS v3
—
CVSS v2
3.3
VIR risk
3.3
Description
The LIXIL Corporation My SATIS Genius Toilet application for Android has a hardcoded Bluetooth PIN, which allows physically proximate attackers to trigger physical resource consumption (water or heat) or user discomfort.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| lixil | my_satis_genius_toilet | - | |
References
- http://arstechnica.com/security/2013/08/holy-sht-smart-toilet-hack-attack/
- http://packetstormsecurity.com/files/122655/LIXIL-Satis-Toilet-Hard-Coded-Bluetooth-PIN.html
- http://seclists.org/fulldisclosure/2013/Aug/18
- http://www.huffingtonpost.co.uk/2013/08/05/smart-toilet-could-attackmy-satis_n_3706116.html
- http://www.independent.co.uk/life-style/gadgets-and-tech/features/now-even-toilets-arent-safe-from-hacking-8747232.html
- https://www.trustwave.com/spiderlabs/advisories/TWSL2013-020.txt
- http://arstechnica.com/security/2013/08/holy-sht-smart-toilet-hack-attack/
- http://packetstormsecurity.com/files/122655/LIXIL-Satis-Toilet-Hard-Coded-Bluetooth-PIN.html
- http://seclists.org/fulldisclosure/2013/Aug/18
- http://www.huffingtonpost.co.uk/2013/08/05/smart-toilet-could-attackmy-satis_n_3706116.html
- http://www.independent.co.uk/life-style/gadgets-and-tech/features/now-even-toilets-arent-safe-from-hacking-8747232.html
- https://www.trustwave.com/spiderlabs/advisories/TWSL2013-020.txt
Verify integrity in audit chain (admin only). AS-IS.