Skip to main content

Vendor/product archive

mobile_devices / c4_obd-ii_dongle_firmware CVEs

Beta · best-effort

3 CVEs tagged to mobile_devices / c4_obd-ii_dongle_firmware3 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2015-2908

Published Aug 23, 2015

Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attack…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2907

Published Aug 23, 2015

Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, have hardcoded SSH credentials, which makes it easier for re…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2906

Published Aug 23, 2015

Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, store SSH private keys that are the same across different cu…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1