CVE-2013-3619

HIGH

Supermicro Onboard IPMI Static SSL Certificate Scanner

Title source: metasploit

Description

Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.

Exploits (1)

metasploit SCANNER
by hdm, juan · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/smt_ipmi_static_cert_scanner.rb

Scores

CVSS v3 8.1
EPSS 0.0946
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (5)
citrix/netscaler_firmware
citrix/netscaler_sd-wan_firmware
citrix/netscaler_sdx_firmware 10
supermicro/smt_x8_firmware < 3.12
supermicro/smt_x9_firmware < 3.15
Published Jan 02, 2020
Tracked Since Feb 18, 2026