PT-2018-13431 · Eaton · Eaton Power Xpert Meter

Published

2018-08-30

·

Updated

2020-08-24

·

CVE-2018-16158

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Eaton Power Xpert Meter versions prior to 13.4.0.10
Description The issue allows remote attackers to perform SSH logins via the PubkeyAuthentication option, making it easier to gain access. This is due to a single SSH private key being used across different customers' installations, and access to this key is not properly restricted.
Recommendations For versions prior to 13.4.0.10, update to version 13.4.0.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the SSH private key to minimize the risk of exploitation.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16158

Affected Products

Eaton Power Xpert Meter