CVE-2013-4786 is a high-severity information disclosure flaw in the IPMI v2.0 specification that allows remote attackers to obtain password hashes for valid accounts via RMCP+ Authenticated Key-Exchange Protocol (RAKP) message responses. This enables offline password guessing attacks. The vulnerability has no patch as it is inherent to the specification.