ZeroHour

CVE-2018-16158

PoC ×2
CVSS 3.0
9.8 critical
EPSS
35%p98
Published
()
Modified
Description

Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option.

Vendors
eaton
Products
power xpert meter 4000 firmware, power xpert meter 6000 firmware, power xpert meter 8000 firmware
Weakness
CWE-798
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.