CVE-2015-2907
Summary
| CVE | CVE-2015-2907 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-23 21:59:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, have hardcoded SSH credentials, which makes it easier for remote attackers to obtain access by leveraging knowledge of the required username and password. |
Risk And Classification
Primary CVSS: v2.0 9 from [email protected]
AV:N/AC:L/Au:S/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Mobile Devices | C4 Obd-ii Dongle Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Munic | Mobile Devices MDI OBD-II Dongles | affected 2.x custom | Not specified |
| CNA | Munic | Mobile Devices MDI OBD-II Dongles | affected 3.4.x custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#209512 - Mobile Devices C4 ODB2 dongle contains multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Fast and Vulnerable: A Story of Telematic Failures | USENIX | af854a3a-2127-422b-91ae-364da2661108 | www.usenix.org | |
| VU#209512 - Mobile Devices C4 ODB2 dongle contains multiple vulnerabilities | MITRE | www.kb.cert.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.