CVE-2021-38547 describes a "Glowworm" attack affecting Logitech Z120 and S120 speakers, where remote attackers can recover speech signals by analyzing the power indicator LED's light intensity. This vulnerability has a CVSS score of 5.9 (Medium), indicating a network-based attack with high complexity, requiring specialized equipment (telescope and electro-optical sensor) to achieve high confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2021-08-09CPE matchmatch criteria | cpe:2.3:o:logitech:z120_firmware:*:*:*:*:*:*:*:* | ||
<= 2021-08-09CPE matchmatch criteria | cpe:2.3:o:logitech:s120_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.