CVE-2015-2908
Summary
| CVE | CVE-2015-2908 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-23 21:59:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Mobile Devices | C4 Obd-ii Dongle Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Munic | Mobile Devices MDI OBD-II Dongles | affected 2.x custom | Not specified |
| CNA | Munic | Mobile Devices MDI OBD-II Dongles | affected 3.4.x custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#209512 - Mobile Devices C4 ODB2 dongle contains multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| Fast and Vulnerable: A Story of Telematic Failures | USENIX | af854a3a-2127-422b-91ae-364da2661108 | www.usenix.org | |
| VU#209512 - Mobile Devices C4 ODB2 dongle contains multiple vulnerabilities | MITRE | www.kb.cert.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.