{"api_version":"1","generated_at":"2026-07-23T04:28:41+00:00","cve":"CVE-2015-2908","urls":{"html":"https://cve.report/CVE-2015-2908","api":"https://cve.report/api/cve/CVE-2015-2908.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-2908","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-2908"},"summary":{"title":"CVE-2015-2908","description":"Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server.","state":"PUBLISHED","assigner":"certcc","published_at":"2015-08-23 21:59:05","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-345","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9","severity":"","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/209512","name":"http://www.kb.cert.org/vuls/id/209512","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Vulnerability Note VU#209512 - Mobile Devices C4 ODB2 dongle contains multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.usenix.org/conference/woot15/workshop-program/presentation/foster","name":"https://www.usenix.org/conference/woot15/workshop-program/presentation/foster","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fast and Vulnerable: A Story of Telematic Failures | USENIX","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/CKIG-9ZAQGX","name":"CONFIRM:http://www.kb.cert.org/vuls/id/CKIG-9ZAQGX","refsource":"MITRE","tags":[],"title":"VU#209512 - Mobile Devices C4 ODB2 dongle contains multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-2908","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-2908","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Munic","product":"Mobile Devices (MDI) OBD-II dongles","version":"affected 2.x custom","platforms":[]},{"source":"CNA","vendor":"Munic","product":"Mobile Devices (MDI) OBD-II dongles","version":"affected 3.4.x custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"2908","vulnerable":"1","versionEndIncluding":"3.4","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"mobile_devices","cpe5":"c4_obd-ii_dongle_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:32:20.499Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_transferred"],"url":"https://www.usenix.org/conference/woot15/workshop-program/presentation/foster"},{"tags":["x_transferred"],"url":"http://www.kb.cert.org/vuls/id/209512"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Mobile Devices (MDI) OBD-II dongles","vendor":"Munic","versions":[{"lessThan":"2.x","status":"affected","version":"0","versionType":"custom"},{"lessThan":"3.4.x","status":"affected","version":"0","versionType":"custom"}]}],"datePublic":"2015-08-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2023-03-01T05:42:18.460Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"url":"https://www.usenix.org/conference/woot15/workshop-program/presentation/foster"},{"url":"http://www.kb.cert.org/vuls/id/209512"}],"x_generator":{"engine":"cveClient/1.0.13"}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2015-2908","datePublished":"2015-08-23T21:00:00.000Z","dateReserved":"2015-04-03T00:00:00.000Z","dateUpdated":"2024-08-06T05:32:20.499Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-08-23 21:59:05","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-345","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:mobile_devices:c4_obd-ii_dongle_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"3.4","matchCriteriaId":"473D9308-AB22-4E49-89A9-DEF8CB2B8E1B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"2908","Ordinal":"1","Title":"CVE-2015-2908","CVE":"CVE-2015-2908","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"2908","Ordinal":"1","NoteData":"Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server.","Type":"Description","Title":"CVE-2015-2908"},{"CveYear":"2015","CveId":"2908","Ordinal":"2","NoteData":"2015-08-23","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"2908","Ordinal":"3","NoteData":"2015-08-23","Type":"Other","Title":"Modified"}]}}}