CVE-2013-4784
high · 10The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
10
CVSS
49.6%
EPSS (exploit prob.)
99th
EPSS percentile
2013-07-08
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hp | integrated_lights-out_bmc | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://fish2.com/ipmi/cipherzero.html
- http://osvdb.org/show/osvdb/93040
- http://www.metasploit.com/modules/auxiliary/scanner/ipmi/ipmi_cipher_zero
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.wired.com/threatlevel/2013/07/ipmi/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85569
- https://lists.gnu.org/archive/html/freeipmi-devel/2013-02/msg00013.html
- http://fish2.com/ipmi/cipherzero.html
- http://osvdb.org/show/osvdb/93040
- http://www.metasploit.com/modules/auxiliary/scanner/ipmi/ipmi_cipher_zero
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.wired.com/threatlevel/2013/07/ipmi/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85569
- https://lists.gnu.org/archive/html/freeipmi-devel/2013-02/msg00013.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-4784