Back to Database
Status published
Critical
CVE-2013-4784
The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers...
Vulnerability Description
The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-4784
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85569
- http://www.wired.com/threatlevel/2013/07/ipmi/
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.metasploit.com/modules/auxiliary/scanner/ipmi/ipmi_cipher_zero
- http://osvdb.org/show/osvdb/93040
- http://fish2.com/ipmi/cipherzero.html
- https://lists.gnu.org/archive/html/freeipmi-devel/2013-02/msg00013.html
More from hp
View All →CVE-2022-48311
**UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet...
Unknown
0
CVE-2022-23456
Potential arbitrary file deletion vulnerability has been identified in HP...
Medium
5.5
CVE-2020-15596
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on...
Medium
6.7
CVE-2019-19539
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and...
Medium
5.5
CVE-2019-16240
A Buffer Overflow and Information Disclosure issue exists in HP...
Critical
9.1
Affected Vendor
Affected Software
integrated lights-out bmc
Vulnerable Versions:
Unknown
Timeline
Official Publish:
July 8th, 2013
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.