Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: certcc

Published: 2015-08-23T21:00:00

Updated: 2023-03-01T05:42:18.460651Z

Reserved: 2015-04-03T00:00:00


Link: CVE-2015-2908

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2015-08-23T21:59:05.217

Modified: 2023-03-01T08:15:09.863


Link: CVE-2015-2908

JSON object: View

cve-icon Redhat Information

No data.

CWE