7.8
CVE-2013-4786
- EPSS 78.57%
- Veröffentlicht 08.07.2013 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
- CVE-Watchlists
- Unerledigt
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Fujitsu M10 Firmware Version <= 2290
Intel ≫ Intelligent Platform Management Interface Version2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 78.57% | 0.995 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:C/I:N/A:N
|
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
http://fish2.com/ipmi/remote-pw-cracking.html
http://marc.info/?l=bugtraq&m=139653661621384&w=2
https://community.rapid7.com/community/metasploit/blog/2013/07/02/a-penetration-testers-guide-to-ipmi
https://nvidia.custhelp.com/app/answers/detail/a_id/5010
https://security.netapp.com/advisory/ntap-20190919-0005/
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04197764