CVE-2021-38546 describes a "Glowworm" attack affecting Creative Pebble speaker devices, including Pebble, Pebble Plus, Pebble V2, and Pebble V3 models. This vulnerability allows remote attackers to recover speech signals by observing the power indicator LED's light intensity, which correlates with the speaker's power consumption and thus the audio being played. Rated Medium severity (CVSS 5.9), the attack requires a telescope and electro-optical sensor, making it a high attack complexity but with a high impact on confidentiality. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021-08-09CPE matchmatch criteria | cpe:2.3:o:creative:pebble_v3_firmware:*:*:*:*:*:*:*:* | ||
<= 2021-08-09CPE matchmatch criteria | cpe:2.3:o:creative:pebble_v2_firmware:*:*:*:*:*:*:*:* | ||
<= 2021-08-09CPE matchmatch criteria | cpe:2.3:o:creative:pebble_firmware:*:*:*:*:*:*:*:* | ||
<= 2021-08-09CPE matchmatch criteria | cpe:2.3:o:creative:pebble_plus_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.