Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-2908

Опубликовано: 23 авг. 2015
Источник: nvd
CVSS2: 9
EPSS Низкий

Описание

Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:mobile_devices:c4_obd-ii_dongle_firmware:*:*:*:*:*:*:*:*
Версия до 3.4 (включая)

EPSS

Процентиль: 72%
0.00724
Низкий

9 Critical

CVSS2

Дефекты

CWE-345

Связанные уязвимости

github
больше 3 лет назад

** DISPUTED ** Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbitrary code by specifying an update server. NOTE: the vendor states "This was a flaw for the developer/debugging devices, and was fixed in production version about 3 years ago."

EPSS

Процентиль: 72%
0.00724
Низкий

9 Critical

CVSS2

Дефекты

CWE-345