CVE-2013-3620: Citrix NetScaler Firmware

High severity, CVSS 7.5. EPSS: 3.6% chance of exploitation in the next 30 days.

Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.

Affected products

  • Citrix NetScaler Firmware: affected versions not specified
  • Citrix NetScaler SD-WAN Firmware: affected versions not specified
  • Citrix NetScaler Sdx Firmware: version 10 only
  • Supermicro Smt x8 Firmware: before 3.12 (fixed in 3.12)
  • Supermicro Smt x9 Firmware: before 3.15 (fixed in 3.15)

Published 2020-01-02. Last modified 2026-06-16.