CVE-2013-3619
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.69%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.69% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- supermicro/smt x9 firmware · supermicro/smt x8 firmware · citrix/netscaler sdx firmware · citrix/netscaler firmware · citrix/netscaler sd-wan firmware
- Source
- cret@cert.org
References
- http://support.citrix.com/article/CTX216642Third Party Advisory
- https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilitiesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89044Third Party Advisory, VDB Entry
- https://support.citrix.com/article/CTX216642Third Party Advisory
- https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdfVendor Advisory
- http://support.citrix.com/article/CTX216642Third Party Advisory
- https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilitiesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89044Third Party Advisory, VDB Entry
- https://support.citrix.com/article/CTX216642Third Party Advisory
- https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.