Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, store SSH private keys that are the same across different customers' installations, which makes it easier for remote attackers to obtain access by leveraging knowledge of a private key from another installation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2015-08-23T21:00:00

Updated: 2024-08-06T05:32:20.590Z

Reserved: 2015-04-03T00:00:00

Link: CVE-2015-2906

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2015-08-23T21:59:02.933

Modified: 2023-02-22T16:15:11.207

Link: CVE-2015-2906

cve-icon Redhat

No data.