Remote Audio Recovery Vulnerability in Logitech Z120 and S120 Speakers
CVE-2021-38547

5.9MEDIUM

Key Information:

Vendor

Logitech

Vendor
CVE Published:
11 August 2021

What is CVE-2021-38547?

The Logitech Z120 and S120 speakers enable a potential security breach where remote attackers can exploit a vulnerability related to the device's power indicator LED. Through the use of a telescope and an electro-optical sensor, an attacker can analyze the variations in LED intensity, which correlate directly with the power consumption of the speakers. This phenomenon occurs because the sound played affects the power usage, thereby allowing the recovery of speech signals from the emitted LED light. This form of attack, often referred to as a 'Glowworm' attack, underlines significant concerns in audio device security and highlights the necessity for robust protective measures.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.