Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, store SSH private keys that are the same across different customers' installations, which makes it easier for remote attackers to obtain access by leveraging knowledge of a private key from another installation.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: certcc

Published: 2015-08-23T21:00:00

Updated: 2023-02-22T15:46:59.871Z

Reserved: 2015-04-03T00:00:00


Link: CVE-2015-2906

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2015-08-23T21:59:02.933

Modified: 2023-02-22T16:15:11.207


Link: CVE-2015-2906

JSON object: View

cve-icon Redhat Information

No data.