CVE-2013-3619: Citrix NetScaler Firmware

High severity, CVSS 8.1. EPSS: 9.7% chance of exploitation in the next 30 days.

Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.

Affected products

  • Citrix NetScaler Firmware: affected versions not specified
  • Citrix NetScaler SD-WAN Firmware: affected versions not specified
  • Citrix NetScaler Sdx Firmware: version 10 only
  • Supermicro Smt x8 Firmware: before 3.12 (fixed in 3.12)
  • Supermicro Smt x9 Firmware: before 3.15 (fixed in 3.15)

Published 2020-01-02. Last modified 2026-06-16.