cbcvebase.
CVE-2013-3619
published 2020-01-02

CVE-2013-3619: Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8…

PriorityP260high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EXPLOIT
EPSS
9.69%
94.9th percentile
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.

Affected

11 ranges
VendorProductVersion rangeFixed in
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixnetscaler_sdx_firmware
citrixxenserver
supermicroipmi
supermicrosmt_x8_firmware< 3.123.12
supermicrosmt_x9_firmware< 3.153.15

Detection & IOCsextracted from sources · hover to see the quote

versionSMT_X9_214
  • Scan for Supermicro IPMI controllers presenting the known static/hardcoded SSL certificate shipped with X9 generation firmware prior to SMT_X9_317 and X8 generation firmware prior to SMT_X8_312. A matching certificate fingerprint indicates a vulnerable, unpatched device.
  • Monitor for use of hardcoded private keys in Lighttpd SSL (HTTPS) and Dropbear SSH services on IPMI management interfaces of Supermicro X8/X9 motherboards; identical certificates/host keys across multiple devices indicate the static key condition.
  • ·Vulnerable scope covers two distinct firmware lines: Supermicro X9 generation motherboards before SMT_X9_317 and X8 generation motherboards before SMT_X8_312. Both the HTTPS (Lighttpd) and SSH (Dropbear) services are affected by separate hardcoded keys.
  • ·The Metasploit auxiliary scanner module (smt_ipmi_static_cert_scanner.rb) was validated against firmware SMT_X9_214 on X9SCL/X9SCM hardware; detections should be confirmed against the actual certificate presented, not solely firmware version strings.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.