Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9...
Vulnerability Description
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-3619
Credits & Attribution
No credits recorded in the NVD database.
References
- https://support.citrix.com/article/CTX216642
- http://support.citrix.com/article/CTX216642
- https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilities
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89044
- https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdf
Affected Vendor
Supermicro
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.