漏洞标题
N/A
漏洞描述信息
JBL Go 2设备直到2021年8月9日才允许远程攻击者从设备上的LED中恢复语音信号,通过望远镜和电光学传感器,也称为“闪耀虫”攻击。扬声器的功率指示LED直接连接到电线上,因此,设备功率指示LED的强度和功率成正比。扬声器播放的声音会影响它们的功率,因此也与LED的亮度成正比。通过分析向扬声器功率指示LED照射的电光学传感器获得的测量值,我们可以恢复它们播放的声音。
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
JBL Go 2 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result, the intensity of a device's power indicator LED is correlative to the power consumption. The sound played by the speakers affects their power consumption and as a result is also correlative to the light intensity of the LEDs. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LEDs of the speakers, we can recover the sound played by them.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
JBL Go 2 安全漏洞
漏洞描述信息
JBL Go 2是日本JBL公司的一个全功能的便携式防水蓝牙音箱。 JBL Go 2 2021-08-09及之前版本存在安全漏洞。远程攻击者通过望远镜和光电传感器(也称为“萤火虫”攻击)从设备上的LED恢复语音信号。扬声器的电源指示LED直接连接到电源线,因此,设备电源指示LED的强度与功耗相关。扬声器播放的声音会影响其功耗,因此也与LED的光强度相关。通过分析从指向扬声器电源指示灯LED的光电传感器获得的测量值,可以恢复扬声器播放的声音
CVSS信息
N/A
漏洞类别
其他