peter bassill · operator
$ cve CVE-2018-16158 JSON

CVE-2018-16158

9.8
CRITICAL · CVSS 3.0 · EPSS 34.9% (pctl 98)

Patch early

EPSS 34.9% — above the 10% action threshold.

Description

Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS34.93% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2018-08-30
Last modified2026-06-17

Affected (6)

VendorProduct
eatonpower xpert meter 4000
eatonpower xpert meter 4000 firmware
eatonpower xpert meter 6000
eatonpower xpert meter 6000 firmware
eatonpower xpert meter 8000
eatonpower xpert meter 8000 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD