CVE-2018-16158
critical · 9.8Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option.
9.8
CVSS
34.9%
EPSS (exploit prob.)
98th
EPSS percentile
2018-08-30
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-798
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| eaton | power_xpert_meter_4000_firmware | < 13.4.0.10 |
| eaton | power_xpert_meter_4000 | all versions |
| eaton | power_xpert_meter_6000_firmware | < 13.4.0.10 |
| eaton | power_xpert_meter_6000 | all versions |
| eaton | power_xpert_meter_8000_firmware | < 13.4.0.10 |
| eaton | power_xpert_meter_8000 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/PXM-Advisory.pdf
- https://www.ctrlu.net/vuln/0006.html
- https://github.com/BrianWGray/msf/blob/master/exploits/linux/ssh/eaton_known_privkey.rb
- http://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/PXM-Advisory.pdf
- https://www.ctrlu.net/vuln/0006.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-16158