@benjojo There’s an IPMI brute-force around, if that's not what you're doing here.
CVE-2013-4786
https://support.hpe.com/hpesc/public/docDisplay?docId=emr_na-c04197764
This is reportedly unfixable on various HP servers.
“HPSBHF02981 rev.4 - HPE Integrated Lights-Out 2, 3, 4, 5 (iLO 2, iLO 3, iLO 4, and iLO 5) and HPE Superdome Flex RMC - IPMI 2.0 RCMP+ Authentication Remote Password Hash Vulnerability (RAKP)”
TL;DR: ask nicely for a weakly-hashed IPMI password, then crack it offline.
On at least some of these boxes, the iLO command that blocks this access:
MP:CM> sa -lanipmi d




🍵 


