Vulnerability intelligence
CVE-2013-4786
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.
CVSS Score
—
Unrated
EPSS — Exploit Probability
79%
Riskier than 100% of all CVEs · checked 2026-09-06
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
3 articles across 3 outlets · first covered Jul 28, 2026 · latest Aug 4, 2026
Coverage timeline
-
CVE-2013-4786 flaw puts thousands of servers at riskwww.securityweek.com · Aug 4, 2026
-
BMCs Leak Password Hashes via CVE-2013-4786, Threatening Cloud AIsecurityonline.info · Aug 3, 2026
-
24,000+ BMCs exposed by 20 year old CVE-2013-4786 flawwww.darkreading.com · Jul 28, 2026