Lucene search

K
nvd[email protected]NVD:CVE-2013-3619
HistoryJan 02, 2020 - 6:15 p.m.

CVE-2013-3619

2020-01-0218:15:11
CWE-798
web.nvd.nist.gov
6

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0.013

Percentile

86.4%

Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.

Affected configurations

Nvd
Node
supermicrosmt_x9_firmwareRange<3.15
AND
supermicrosh7758Match-
Node
supermicrosmt_x8_firmwareRange<3.12
AND
supermicrosh7757Match-
Node
citrixnetscaler_sdx_firmwareMatch10
AND
citrixnetscaler_sdxMatch-
Node
citrixnetscaler_firmwareMatch-
AND
citrixnetscalerMatch-
Node
citrixnetscaler_sd-wan_firmwareMatch-
AND
citrixnetscaler_sd-wanMatch-
VendorProductVersionCPE
supermicrosmt_x9_firmware*cpe:2.3:o:supermicro:smt_x9_firmware:*:*:*:*:*:*:*:*
supermicrosh7758-cpe:2.3:h:supermicro:sh7758:-:*:*:*:*:*:*:*
supermicrosmt_x8_firmware*cpe:2.3:o:supermicro:smt_x8_firmware:*:*:*:*:*:*:*:*
supermicrosh7757-cpe:2.3:h:supermicro:sh7757:-:*:*:*:*:*:*:*
citrixnetscaler_sdx_firmware10cpe:2.3:o:citrix:netscaler_sdx_firmware:10:*:*:*:*:*:*:*
citrixnetscaler_sdx-cpe:2.3:h:citrix:netscaler_sdx:-:*:*:*:*:*:*:*
citrixnetscaler_firmware-cpe:2.3:o:citrix:netscaler_firmware:-:*:*:*:*:*:*:*
citrixnetscaler-cpe:2.3:h:citrix:netscaler:-:*:*:*:*:*:*:*
citrixnetscaler_sd-wan_firmware-cpe:2.3:o:citrix:netscaler_sd-wan_firmware:-:*:*:*:*:*:*:*
citrixnetscaler_sd-wan-cpe:2.3:h:citrix:netscaler_sd-wan:-:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0.013

Percentile

86.4%