← Vulnerability feed

Vulnerability record · CVE-2013-4784 · published 8 July 2013

CVE-2013-4784: HP Integrated Lights-Out BMC authentication bypass via cipher zero

Hp · Integrated Lights Out Bmc

The HP Integrated Lights-Out (iLO) BMC implementation accepts IPMI cipher suite 0 (cipher zero) with an arbitrary password, allowing authentication to be bypassed. An attacker who can reach the IPMI interface can then execute arbitrary IPMI commands on the managed server. This is a full compromise of the BMC's authentication control.

10.0 CVSS 2.0 High EPSS 50% · top 1.1% CWE-287 · Improper authentication
10.0CVSS 2.0 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution on the BMC with a CVSS 2.0 score of 10, public exploit tooling and very high EPSS, though not in KEV.

What it is

The HP Integrated Lights-Out (iLO) BMC implementation accepts IPMI cipher suite 0 (cipher zero) with an arbitrary password, allowing authentication to be bypassed. An attacker who can reach the IPMI interface can then execute arbitrary IPMI commands on the managed server. This is a full compromise of the BMC's authentication control.

Impact

An attacker gains unauthenticated execution of arbitrary IPMI commands, which can include power control, console access, virtual media mounting and credential manipulation on the managed host. That effectively yields control of the server through its out-of-band management interface.

Attack surface

The flaw is reachable over the network via the IPMI interface (AV:N, AC:L, Au:N per the CVSS 2.0 vector), requiring no authentication and no user interaction. Any host that can route to the BMC's IPMI port can attempt the cipher zero handshake.

Exploitation

CISA KEV does not list this CVE, but EPSS is 0.49587 (98.8th percentile), indicating high predicted exploitation activity. A public Metasploit auxiliary scanner module (ipmi_cipher_zero) exists, so exploitation tooling is readily available.

What to do

  • Apply the vendor fix for the affected iLO firmware; check HP/HPE advisories for the corrected version since the record does not list one.
  • Disable IPMI cipher suite 0 (cipher zero) on all BMCs that support the setting.
  • Restrict IPMI/BMC network access to a dedicated management VLAN or out-of-band network with strict firewall rules.
  • Change default and weak BMC credentials and audit for unauthorized accounts or configuration changes.
  • Where IPMI is not required, disable the service or the BMC network interface entirely.

Detection

  • Monitor IPMI traffic for negotiation or use of cipher suite 0 on UDP 623.
  • Alert on IPMI authentication attempts using cipher zero or anomalous usernames/passwords.
  • Audit BMC logs for unexpected power, console, virtual media or user-account changes.
  • Scan the management network for BMCs exposing IPMI to untrusted segments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4784 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed9.8CVE-2023-49105ownCloud Server WebDAV authentication bypass via pre-signed URLsownCloud core before 10.13.1 accepts pre-signed URLs even when the file owner has no signing-key configured, so the signature check is effectively sk…KEVEPSS 43%analysed9.8CVE-2026-65400Apple macOS Screen Sharing authentication bypassAn improper authentication flaw in Apple macOS Screen Sharing allows a network attacker to authenticate without valid credentials. Apple fixed it via…KEVEPSS 1.2%analysed9.3CVE-2026-16232Check Point SmartConsole authentication bypass grants admin tokenCheck Point SmartConsole login contains an improper authentication flaw (CWE-287) that lets an unauthenticated remote attacker obtain an application …KEVEPSS 78%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed

Source: NIST National Vulnerability Database (record CVE-2013-4784), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.