CVE-2013-3619
published 2020-01-02CVE-2013-3619: Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8…
PriorityP260high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EXPLOIT
EPSS
9.69%
94.9th percentile
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | netscaler_sdx_firmware | — | — |
| citrix | xenserver | — | — |
| supermicro | ipmi | — | — |
| supermicro | smt_x8_firmware | < 3.12 | 3.12 |
| supermicro | smt_x9_firmware | < 3.15 | 3.15 |
Detection & IOCsextracted from sources · hover to see the quote
- →Scan for Supermicro IPMI controllers presenting the known static/hardcoded SSL certificate shipped with X9 generation firmware prior to SMT_X9_317 and X8 generation firmware prior to SMT_X8_312. A matching certificate fingerprint indicates a vulnerable, unpatched device. ↗
- →Monitor for use of hardcoded private keys in Lighttpd SSL (HTTPS) and Dropbear SSH services on IPMI management interfaces of Supermicro X8/X9 motherboards; identical certificates/host keys across multiple devices indicate the static key condition. ↗
- ·Vulnerable scope covers two distinct firmware lines: Supermicro X9 generation motherboards before SMT_X9_317 and X8 generation motherboards before SMT_X8_312. Both the HTTPS (Lighttpd) and SSH (Dropbear) services are affected by separate hardcoded keys. ↗
- ·The Metasploit auxiliary scanner module (smt_ipmi_static_cert_scanner.rb) was validated against firmware SMT_X9_214 on X9SCL/X9SCM hardware; detections should be confirmed against the actual certificate presented, not solely firmware version strings. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9x36-hp8r-pf6p: Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro
ghsa_unreviewed·2022-05-05
CVE-2013-3619 [MEDIUM] GHSA-9x36-hp8r-pf6p: Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
Citrix
Citrix Security Bulletin CTX216642
vendor_citrix·CVSS 8.1
CVE-2013-3619 [HIGH] Citrix Security Bulletin CTX216642
Citrix Security Bulletin CTX216642
CVE References: CVE-2013-3619, CVE-2013-3620, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No writeups or analysis indexed.
http://support.citrix.com/article/CTX216642https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilitieshttps://exchange.xforce.ibmcloud.com/vulnerabilities/89044https://support.citrix.com/article/CTX216642https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdfhttp://support.citrix.com/article/CTX216642https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilitieshttps://exchange.xforce.ibmcloud.com/vulnerabilities/89044https://support.citrix.com/article/CTX216642https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdf
2020-01-02
Published