CVE-2013-4786
Publication date 8 July 2013
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| freeipmi | ||
| openipmi | ||
Notes
jdstrand
protocol problem. Not clear if fixes also need to be addressed in freeipmi and openipmi per Debian: "Contacted relevant maintainers: Since few to no devices do mutual authentication, tools shipped by Debian are generally not affected. At best, the tools can print a warning for vulnerable devices."
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.5 · High
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N