PT-2015-5967 · Mobile Devices · Mobile Devices C4 Obd-Ii Dongle

Published

2015-08-23

·

Updated

2023-02-22

·

CVE-2015-2906

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mobile Devices (aka MDI) C4 OBD-II dongles versions 2.x through 3.4.x
Description The issue allows remote attackers to gain access by leveraging knowledge of a private key from another installation, as the SSH private keys stored are the same across different customers' installations.
Recommendations For versions 2.x through 3.4.x, consider disabling SSH access until a patch or firmware update that generates unique SSH private keys for each installation is available. Restrict access to the device to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2015-2906

Affected Products

Mobile Devices C4 Obd-Ii Dongle