« Volver al listado

CVE-2013-4782

Estado: ModificadaAlta (10)—

The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-4782",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-07-08T22:55:01.107",
  "references": [
    {
      "url": "http://fish2.com/ipmi/cipherzero.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/show/osvdb/93038",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.metasploit.com/modules/auxiliary/scanner/ipmi/ipmi_cipher_zero",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.wired.com/threatlevel/2013/07/ipmi/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.gnu.org/archive/html/freeipmi-devel/2013-02/msg00013.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://fish2.com/ipmi/cipherzero.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/show/osvdb/93038",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.metasploit.com/modules/auxiliary/scanner/ipmi/ipmi_cipher_zero",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.wired.com/threatlevel/2013/07/ipmi/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.gnu.org/archive/html/freeipmi-devel/2013-02/msg00013.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password."
    },
    {
      "lang": "es",
      "value": "El Supermicro implementacion de BMC permite a atacantes remotos evitar la autenticación y ejecutar comandos IPMI mediante el uso de cifrado Suite 0 (también conocido como cifra cero) y una contraseña arbitraria."
    }
  ],
  "lastModified": "2026-06-16T23:57:53.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:supermicro:bmc:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7CE4381-EE10-49D4-A895-964F05D0ADA9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}