What is CVE-2013-4786?
CVE-2013-4786 is a 20-year-old vulnerability in the IPMI 2.0 protocol that allows pre-authentication disclosure of password-derived hashes. It affected over 36,000 internet-exposed BMC systems, enabling easy password cracking and potentially full compromise of data centers. Affected systems should be immediately isolated from the network and IPMI passwords changed to complex ones.
Azərbaycanca: CVE-2013-4786, 20 il əvvəl aşkarlanmış IPMI 2.0 protokol zəifliyidir, hansı ki, autentifikasiya olmadan parol heşlərini sızdırır. 36 mindən çox açıq BMC (Baseboard Management Controller) sistemini təsirləndirib və parolların asanlıqla qırılmasına imkan verərək, data mərkəzlərinin tam ələ keçirilməsi riskini yaradır. Təsirlənmiş sistemlərin dərhal şəbəkədən təcrid edilməsi və IPMI parollarının mürəkkəb ilə yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What dangerous information does the CVE-2013-4786 vulnerability leak in the IPMI system?
CVE-2013-4786 causes the disclosure of password-derived hashes without requiring any authentication.
What immediate measures should be taken against the CVE-2013-4786 vulnerability?
Affected systems should be immediately isolated from the network and IPMI passwords must be updated with complex ones.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.