PT-2021-22203 · Jbl · Jbl Go 2

Ben Nassi

+4

·

Published

2021-08-11

·

Updated

2021-08-23

·

CVE-2021-38548

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions JBL Go 2 devices through 2021-08-09
Description The issue allows remote attackers to recover speech signals from an LED on the device via a telescope and an electro-optical sensor, also known as a "Glowworm" attack. This is possible because the power indicator LED of the speakers is connected directly to the power line, making the intensity of the device's power indicator LED correlative to the power consumption. The sound played by the speakers affects their power consumption, which is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, it is possible to recover the sound played by them.
Recommendations For JBL Go 2 devices through 2021-08-09, consider disabling the power indicator LED to minimize the risk of exploitation until a fix is available. Restrict access to the device's power line to prevent unauthorized measurement of power consumption. Avoid using the device in environments where it can be easily monitored with a telescope and an electro-optical sensor. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-38548

Affected Products

Jbl Go 2