High severity7.5NVD Advisory· Published Jul 8, 2013· Updated Jun 16, 2026
CVE-2013-4786
CVE-2013-4786
Description
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:intel:intelligent_platform_management_interface:2.0:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:fujitsu_m10_firmware:*:*:*:*:*:*:*:*Range: <=2290
Patches
Vulnerability mechanics
References
7- fish2.com/ipmi/remote-pw-cracking.htmlnvd
- marc.infonvd
- www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlnvd
- community.rapid7.com/community/metasploit/blog/2013/07/02/a-penetration-testers-guide-to-ipminvd
- nvidia.custhelp.com/app/answers/detail/a_id/5010nvd
- security.netapp.com/advisory/ntap-20190919-0005/nvd
- support.hpe.com/hpsc/doc/public/displaynvd
News mentions
7- Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to AttacksSecurityWeek · Aug 4, 2026
- Weekly Cyber Security Newsletter– Claude Hacked 3 Companies, Cisco 0-Day, Word Copilot and VMware Flaw +20 StoriesCyber Security News · Aug 2, 2026
- 20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in MinutesCyber Security News · Jul 29, 2026
- Thousands of Data Center Controllers Open to TakeoverDark Reading · Jul 28, 2026
- 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginThe Hacker News · Jul 28, 2026
- Over 24,000 exposed server BMCs leak password hash via decades-old flawBleepingComputer · Jul 28, 2026
- Exposed BMCs hand out password hashes before loginHelp Net Security · Jul 28, 2026