Vendor
JBL
Products
6
CVEs
3
Across products
6
Status
Private
Products
6- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-28155 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2021 | The Bluetooth Classic implementation on JBL TUNE500BT devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown a device by flooding the target device with LMP Feature… | ||
| CVE-2023-37215 | Med | 0.40 | 6.2 | 0.00 | Jul 30, 2023 | JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials | ||
| CVE-2021-38548 | Med | 0.38 | 5.9 | 0.01 | Aug 11, 2021 | JBL Go 2 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result,… |
- risk 0.42cvss 6.5epss 0.00
The Bluetooth Classic implementation on JBL TUNE500BT devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown a device by flooding the target device with LMP Feature…
- risk 0.40cvss 6.2epss 0.00
JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials
- risk 0.38cvss 5.9epss 0.01
JBL Go 2 devices through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. The power indicator LED of the speakers is connected directly to the power line, as a result,…