mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 10:09:29 +02:00
19 lines
817 B
Markdown
19 lines
817 B
Markdown
### [CVE-2013-4786](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4786)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
|
|
|
|
#### Github
|
|
- https://github.com/CVEDB/awesome-cve-repo
|
|
- https://github.com/fin3ss3g0d/CosmicRakp
|
|
|