CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2013-4786: IPMI v2.0 Password Hash Disclosure Vulnerability

July 28, 2026

CVE-2013-4786 is a high-severity information disclosure flaw in the IPMI v2.0 specification that allows remote attackers to obtain password hashes for valid accounts via RMCP+ Authenticated Key-Exchange Protocol (RAKP) message responses. This enables offline password guessing attacks. The vulnerability has no patch as it is inherent to the specification.