← back

CVE-2013-4786

HIGH · 7.5 EPSS 78.6%
hype LIKELY HACK · 72 hack

Confirmed large-scale exposure and active scanning; no KEV or PoC weaponization yet; vendor research may oversell but defenders responding operationally.

What: IPMI 2.0 BMC authentication flaw (CVE-2013-4786) allows unauthenticated attackers to extract password hashes via RAKP handshake before login (CVSS 7.5).

Why it matters: A 13-year-old protocol-level vulnerability with no patch possible; recent reconnaissance found 24,650+ internet-exposed BMCs (iLO, iDRAC, Supermicro) leaking hashes. Active scanning and weak credential abuse reported on HPE systems. No KEV listing, but scale and defender urgency (rotate factory passwords, air-gap BMCs) signal real triage activity.

Where it's seen: Threat intel reports citing 36k+ exposed BMCs; Bluesky debate over vendor-sponsored research; defenders discussing mitigation (network isolation, credential rotation); no working exploit PoC or 0-day claims, but operational reconnaissance widely documented.

RISK: HIGH — 24k+ exposed systems leaking hashes in-the-wild; protocol flaw unfixable; weak passwords at scale enable offline cracking.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 7/29/2026, 12:13:08 AM

Description

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

CVSS 3.0 breakdown

Exploitability 3.9 · Impact 3.6
vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected versions

  • oracle/fujitsu_m10_firmware
    • ≤ 2290
  • intel/intelligent_platform_management_interface
    • 2.0

Weaknesses

Vendors

  • oracle
  • intel

Products

  • fujitsu_m10_firmware
  • intelligent_platform_management_interface