CVE-2013-3619
Summary
| CVE | CVE-2013-3619 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-02 18:15:00 UTC |
| Updated | 2020-01-15 14:08:00 UTC |
| Description | Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Citrix | Netscaler | - | All | All | All |
| Hardware | Citrix | Netscaler | - | All | All | All |
| Operating System | Citrix | Netscaler Firmware | - | All | All | All |
| Operating System | Citrix | Netscaler Firmware | - | All | All | All |
| Hardware | Citrix | Netscaler Sd-wan | - | All | All | All |
| Hardware | Citrix | Netscaler Sd-wan | - | All | All | All |
| Operating System | Citrix | Netscaler Sd-wan Firmware | - | All | All | All |
| Operating System | Citrix | Netscaler Sd-wan Firmware | - | All | All | All |
| Hardware | Citrix | Netscaler Sdx | - | All | All | All |
| Hardware | Citrix | Netscaler Sdx | - | All | All | All |
| Operating System | Citrix | Netscaler Sdx Firmware | 10 | All | All | All |
| Operating System | Citrix | Netscaler Sdx Firmware | 10 | All | All | All |
| Hardware | Supermicro | Sh7757 | - | All | All | All |
| Hardware | Supermicro | Sh7757 | - | All | All | All |
| Hardware | Supermicro | Sh7758 | - | All | All | All |
| Hardware | Supermicro | Sh7758 | - | All | All | All |
| Operating System | Supermicro | Smt X8 Firmware | All | All | All | All |
| Operating System | Supermicro | Smt X8 Firmware | All | All | All | All |
| Operating System | Supermicro | Smt X9 Firmware | All | All | All | All |
| Operating System | Supermicro | Smt X9 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Security Vulnerabilities in Citrix NetScaler Platform IPMI Lights Out Management (LOM) firmware | CONFIRM | support.citrix.com | Third Party Advisory |
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Multiple Security Vulnerabilities in Citrix NetScaler Platform IPMI Lights Out Management (LOM) firmware | CONFIRM | support.citrix.com | Third Party Advisory |
| www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdf | CONFIRM | www.supermicro.com | Vendor Advisory |
| Metasploit: Supermicro IPMI Firmware Vulnerabil... | SecurityStreet | MISC | community.rapid7.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.