Remote Audio Recovery Vulnerability in Logitech Z120 and S120 Speakers
CVE-2021-38547
5.9MEDIUM
What is CVE-2021-38547?
The Logitech Z120 and S120 speakers enable a potential security breach where remote attackers can exploit a vulnerability related to the device's power indicator LED. Through the use of a telescope and an electro-optical sensor, an attacker can analyze the variations in LED intensity, which correlate directly with the power consumption of the speakers. This phenomenon occurs because the sound played affects the power usage, thereby allowing the recovery of speech signals from the emitted LED light. This form of attack, often referred to as a 'Glowworm' attack, underlines significant concerns in audio device security and highlights the necessity for robust protective measures.
