CVE-2018-16158
Summary
| CVE | CVE-2018-16158 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-30 05:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Eaton | Power Xpert Meter 4000 | - | All | All | All |
| Hardware | Eaton | Power Xpert Meter 4000 | - | All | All | All |
| Operating System | Eaton | Power Xpert Meter 4000 Firmware | All | All | All | All |
| Operating System | Eaton | Power Xpert Meter 4000 Firmware | All | All | All | All |
| Hardware | Eaton | Power Xpert Meter 6000 | - | All | All | All |
| Hardware | Eaton | Power Xpert Meter 6000 | - | All | All | All |
| Operating System | Eaton | Power Xpert Meter 6000 Firmware | All | All | All | All |
| Operating System | Eaton | Power Xpert Meter 6000 Firmware | All | All | All | All |
| Hardware | Eaton | Power Xpert Meter 8000 | - | All | All | All |
| Hardware | Eaton | Power Xpert Meter 8000 | - | All | All | All |
| Operating System | Eaton | Power Xpert Meter 8000 Firmware | All | All | All | All |
| Operating System | Eaton | Power Xpert Meter 8000 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/securit... | MISC | www.eaton.com | Vendor Advisory |
| msf/eaton_known_privkey.rb at master · BrianWGray/msf · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| Something Broken - CTRLu.Net | MISC | www.ctrlu.net | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.