Vulnerability record · CVE-2013-4784 · published 8 July 2013
CVE-2013-4784: HP Integrated Lights-Out BMC authentication bypass via cipher zero
Hp · Integrated Lights Out Bmc
The HP Integrated Lights-Out (iLO) BMC implementation accepts IPMI cipher suite 0 (cipher zero) with an arbitrary password, allowing authentication to be bypassed. An attacker who can reach the IPMI interface can then execute arbitrary IPMI commands on the managed server. This is a full compromise of the BMC's authentication control.
Description
The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution on the BMC with a CVSS 2.0 score of 10, public exploit tooling and very high EPSS, though not in KEV.
What it is
The HP Integrated Lights-Out (iLO) BMC implementation accepts IPMI cipher suite 0 (cipher zero) with an arbitrary password, allowing authentication to be bypassed. An attacker who can reach the IPMI interface can then execute arbitrary IPMI commands on the managed server. This is a full compromise of the BMC's authentication control.
Impact
An attacker gains unauthenticated execution of arbitrary IPMI commands, which can include power control, console access, virtual media mounting and credential manipulation on the managed host. That effectively yields control of the server through its out-of-band management interface.
Attack surface
The flaw is reachable over the network via the IPMI interface (AV:N, AC:L, Au:N per the CVSS 2.0 vector), requiring no authentication and no user interaction. Any host that can route to the BMC's IPMI port can attempt the cipher zero handshake.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.49587 (98.8th percentile), indicating high predicted exploitation activity. A public Metasploit auxiliary scanner module (ipmi_cipher_zero) exists, so exploitation tooling is readily available.
What to do
- Apply the vendor fix for the affected iLO firmware; check HP/HPE advisories for the corrected version since the record does not list one.
- Disable IPMI cipher suite 0 (cipher zero) on all BMCs that support the setting.
- Restrict IPMI/BMC network access to a dedicated management VLAN or out-of-band network with strict firewall rules.
- Change default and weak BMC credentials and audit for unauthorized accounts or configuration changes.
- Where IPMI is not required, disable the service or the BMC network interface entirely.
Detection
- Monitor IPMI traffic for negotiation or use of cipher suite 0 on UDP 623.
- Alert on IPMI authentication attempts using cipher zero or anomalous usernames/passwords.
- Audit BMC logs for unexpected power, console, virtual media or user-account changes.
- Scan the management network for BMCs exposing IPMI to untrusted segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-4784 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-4784), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.