Lucene search

K
cve[email protected]CVE-2013-3619
HistoryJan 02, 2020 - 6:15 p.m.

CVE-2013-3619

2020-01-0218:15:11
CWE-798
web.nvd.nist.gov
185
cve-2013-3619
ipmi
firmware
supermicro
x9
x8
hardcoded
encryption keys
lighttpd
web server
ssl
dropbear
ssh
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.5%

Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.

Affected configurations

NVD
Node
supermicrosmt_x9_firmwareRange<3.15
AND
supermicrosh7758Match-
Node
supermicrosmt_x8_firmwareRange<3.12
AND
supermicrosh7757Match-
Node
citrixnetscaler_sdx_firmwareMatch10
AND
citrixnetscaler_sdxMatch-
Node
citrixnetscaler_firmwareMatch-
AND
citrixnetscalerMatch-
Node
citrixnetscaler_sd-wan_firmwareMatch-
AND
citrixnetscaler_sd-wanMatch-

CNA Affected

[
  {
    "product": "IPMI",
    "vendor": "Supermicro",
    "versions": [
      {
        "status": "affected",
        "version": "before SMT_X9_317 and before SMT X8 312"
      }
    ]
  }
]

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.5%