The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.
https://hackread.com/ipmi-flaw-exposes-servers-offline-password-cracking/
https://www.helpnetsecurity.com/2026/07/28/exposed-bmc-ipmi-vulnerability-research/
https://www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04197764
https://security.netapp.com/advisory/ntap-20190919-0005/
https://nvidia.custhelp.com/app/answers/detail/a_id/5010
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
Published: 2013-07-08
Updated: 2026-06-16
Base Score: 7.8
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N
Severity: High
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity: High
EPSS: 0.7857
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored