CVE-2013-3619
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 9.7%
from disclosure to weapon0 days
Published on NVDJan 2
metasploitNov 6
exploitation probability
9.7%top 5% of all CVEs
observed exploitation
nono source reports it
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
Affected products
Supermicro · IPMIReferences
https://community.rapid7.com/community/metasploit/blog/2013/11/05/supermicro-ipmi-firmware-vulnerabilitieshttps://exchange.xforce.ibmcloud.com/vulnerabilities/89044https://support.citrix.com/article/CTX216642http://support.citrix.com/article/CTX216642https://www.supermicro.com/products/nfo/files/IPMI/CVE_Update.pdf