Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2013-4786

EPSS 67.84% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-4786

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Intelligent Platform Management Interface 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Intelligent Platform Management Interface(IPMI,智能平台管理接口)是一种Intel架构的企业系统的周边设备所采用的一种工业标准。IPMI亦是一个开放的免费标准,用户无需支付额外的费用即可使用此标准。IPMI 能够横跨不同的操作系统、固件和硬件平台,可以智能的监控、控制和自动回报大量服务器的运作状况,以降低服务器系统成本。 Intelligent Platform Management Interface(IPMI,智能平台管理接口)2.0版本规范支持的RMCP
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-4786

#POC DescriptionSource LinkShenlong Link
1CVE-2013-4786 Go exploitation toolhttps://github.com/fin3ss3g0d/CosmicRakpPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-4786

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-07-08 · 22 CVEs total

CVE-2013-2202WordPress XML External Entity注入漏洞
CVE-2013-1615Symantec Security Information Manager 信息泄露漏洞
CVE-2013-1614Symantec Security Information Manager 跨站脚本和HTML注入漏洞
CVE-2013-1613Symantec Security Information Manager SQL注入漏洞
CVE-2013-1414Fortinet FortiOS on FortiGate 多个跨站请求伪造漏洞
CVE-2013-1059Linux kernel net/ceph/auth_none.c拒绝服务漏洞
CVE-2013-3273EMC RSA Authentication Manager 信息泄露漏洞
CVE-2013-3272EMC Replication Manager信息泄露漏洞
CVE-2013-2205WordPress ‘SWFUpload’库多个跨站脚本漏洞
CVE-2013-2204WordPress 内容欺骗漏洞
CVE-2013-2203WordPress 文件上传路径泄露漏洞
CVE-2013-4782Supermicro IPMI BMC实现认证绕过漏洞
CVE-2013-2201WordPress 多个跨站脚本漏洞
CVE-2013-2200WordPress 远程提权漏洞
CVE-2013-2199WordPress 服务器端请求伪造漏洞
CVE-2013-0237WordPress Plupload插件未明跨站脚本漏洞
CVE-2013-0236WordPress 多个跨站脚本漏洞
CVE-2013-0235WordPress XMLRPC API 服务器端请求伪造漏洞
CVE-2013-4785Dell iDRAC 6防火墙Web接口安全漏洞
CVE-2013-4784HP Integrated Lights-Out BMC实现安全绕过漏洞

Showing top 20 of 22 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-4786

No comments yet


Leave a comment