Check Point Reference: | CPAI-2013-3546 |
Date Published: | 12 Nov 2013 |
Severity: | High |
Last Updated: | Saturday 04 January, 2025 |
Source: | CVE-2013-3619 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | IPMI in Supermicro servers |
Vulnerability Description | An SSL keys handling flaw has been reported in Supermicro IPMI firmware. |
Vulnerability Details | A remote attacker could leverage this flaw to intercept SSL traffic to the firmware, using a certain SSL key. Successful exploitation would allow an attacker to view undisclosed information. |
This protection will detect and block attempts to exploit this vulnerability.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
SmartView Tracker will log the following entries:
Attack Name: OpenSSL Enforcement Violation
Attack Information: Supermicro Onboard IPMI Static SSL Certificate Scanner Information Disclosure