CVE-2013-4784

HP Integrated Lights-Out BMC - Unauthenticated Authentication Bypass via Cipher Zero

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-4784. PoCs published by alexoslabs.

AI-analyzed exploit summary This repository contains a Bash script that tests for the IPMI cipher type zero authentication bypass vulnerability (CVE-2013-4784). It uses `ipmitool` to exploit the vulnerability by sending a request with cipher suite 0 and an arbitrary password to bypass authentication and retrieve administrative session information.

Description

The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.

Exploits (1)

nomisec WORKING POC
by alexoslabs · poc
https://github.com/alexoslabs/ipmitest

This repository contains a Bash script that tests for the IPMI cipher type zero authentication bypass vulnerability (CVE-2013-4784). It uses `ipmitool` to exploit the vulnerability by sending a request with cipher suite 0 and an arbitrary password to bypass authentication and retrieve administrative session information.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: IPMI (Intelligent Platform Management Interface) with vulnerable implementations
No auth needed
Prerequisites: ipmitool installed · network access to target IPMI interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Various Sources x_refsource_misc
http://www.wired.com/threatlevel/2013/07/ipmi/
Various Sources x_refsource_misc
http://fish2.com/ipmi/cipherzero.html
Various Sources mailing-list x_refsource_mlist
https://lists.gnu.org/archive/html/freeipmi-devel/2013-02/msg00013.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/85569
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/93040

Scores

EPSS 0.4971
EPSS Percentile 97.9%

Details

CWE
CWE-287
Status published
Products (1)
hp/integrated_lights-out_bmc
Published Jul 08, 2013
Tracked Since Feb 18, 2026