PT-2018-13431 · Eaton · Eaton Power Xpert Meter

Publicado

2018-08-30

·

Atualizado

2020-08-24

·

CVE-2018-16158

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Eaton Power Xpert Meter versions prior to 13.4.0.10
Description The issue allows remote attackers to perform SSH logins via the PubkeyAuthentication option, making it easier to gain access. This is due to a single SSH private key being used across different customers' installations, and access to this key is not properly restricted.
Recommendations For versions prior to 13.4.0.10, update to version 13.4.0.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the SSH private key to minimize the risk of exploitation.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16158

Produtos afetados

Eaton Power Xpert Meter