CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2018-16158

CVSS 9.8v3.0pub. 2018-08-30upd. 2024-11-21

Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Eaton Power Xpert Meter 4000

    HW
    Eaton
    all versions
  • Eaton Power Xpert Meter 4000 Firmware

    OS
    Eaton
    < 13.4.0.10
  • Eaton Power Xpert Meter 6000

    HW
    Eaton
    all versions
  • Eaton Power Xpert Meter 6000 Firmware

    OS
    Eaton
    < 13.4.0.10
  • Eaton Power Xpert Meter 8000

    HW
    Eaton
    all versions
  • Eaton Power Xpert Meter 8000 Firmware

    OS
    Eaton
    < 13.4.0.10
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2021-23281CRITICAL10.0PL ✓same vendor

Eaton IPM – nieuwierzytelniony RCE przez fałszywy serwer SNMP

CVE-2018-8847CRITICAL9.8PL ✓same vendor

Stack-based buffer overflow w Eaton 9000X Drive umożliwiający RCE

CVE-2018-12031CRITICAL9.8PL ✓same vendor

Path Traversal (LFI) w Eaton Intelligent Power Manager v1.6

CVE-2026-22619HIGH7.8same vendor

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could...

CVE-2025-59887HIGH8.6same vendor

Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary...