High severity8.1NVD Advisory· Published Jan 2, 2020· Updated Jun 16, 2026
CVE-2013-3619
CVE-2013-3619
Description
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
Affected products
7- cpe:2.3:o:citrix:netscaler_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:citrix:netscaler_sd-wan_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:citrix:netscaler_sdx_firmware:10:*:*:*:*:*:*:*
- Range: <SMT_X9_317 (X9 generation), <SMT X8 312 (X8 generation)
- Supermicro/IPMIv5Range: before SMT_X9_317 and before SMT X8 312
Patches
Vulnerability mechanics
References
5- support.citrix.com/article/CTX216642nvdThird Party Advisory
- community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilitiesnvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/89044nvdThird Party AdvisoryVDB Entry
- support.citrix.com/article/CTX216642nvdThird Party Advisory
- www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.