漏洞标题
N/A
漏洞描述信息
2021-08-09 创造性的petrel设备允许远程攻击者从设备上的LED,通过望远镜和电光学传感器恢复语音信号,也被称为“光虫”攻击。扬声器的功率指示LED直接连接到电线上,因此,设备功率指示LED的强度和功率是相关的。扬声器播放的声音会影响它们的功率,因此也会影响LED的亮度。通过分析向扬声器功率指示LED发送的电光学传感器获得的数据,我们可以恢复它们播放的声音。
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
CREATIVE Pebble devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Pebble 安全漏洞
漏洞描述信息
Pebble是美国Pebble公司的一款可定制手表。 Pebble 存在安全漏洞,该漏洞源于设备在某些特定的使用情况下,该设备为音频输出设备供电时会出现问题。攻击者可利用该漏洞通过望远镜和光电传感器从设备上的LED恢复语音信号,即“萤火虫”攻击。
CVSS信息
N/A
漏洞类别
其他