« Volver al listado

CVE-2020-5349

Estado: ModificadaCrítica (9.8)—

Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability. A remote unauthenticated malicious user could exploit this vulnerability and gain administrative privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (13)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-5349",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "Networking",
          "versions": [
            {
              "status": "affected",
              "version": "S4100 and S5200"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-07-19T22:15:09.543",
  "references": [
    {
      "url": "https://www.dell.com/support/article/en-us/sln320599/dsa-2020-074-dell-networking-security-update-for-a-hardcoded-credential-vulnerability?lang=en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/article/en-us/sln320599/dsa-2020-074-dell-networking-security-update-for-a-hardcoded-credential-vulnerability?lang=en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability. A remote unauthenticated malicious user could exploit this vulnerability and gain administrative privileges."
    },
    {
      "lang": "es",
      "value": "Unos Switches de la serie S4100 y S5200 de Dell EMC Networking fabricados antes de febrero de 2020, contiene una vulnerabilidad de credenciales embebidas. Un usuario remoto malicioso no autenticado podría explotar esta vulnerabilidad y alcanzar privilegios administrativos"
    }
  ],
  "lastModified": "2026-06-17T03:21:19.597",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s4112f-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D02D4B2-E19F-4CBB-97AB-14E7CF3D6172"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s4112t-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFD2734C-1923-4444-99C0-4B1173192663"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s4128f-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "099EEDE4-9FB9-476A-A5E7-7E18CCF0699E"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s4128t-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5CBC051-656D-49FF-8D8E-2263192F10DB"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s4148f-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "819B6723-52E7-4A24-B1C5-A14F55B818E4"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s4148fe-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D06DF60-F76E-46C0-A10F-0FEA676D2A96"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s4148t-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4987C920-C116-4539-A765-4A81EA501694"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s4148u-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A82800B3-A769-4FC2-B4A6-4A68C0717BAE"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s5212f-on:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91A39661-442C-476F-88BD-1A82F6743676"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s5224f-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C0DF2A9-05EA-4273-9949-9E26836603CB"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s5232f-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE63E704-8E5A-4248-88C5-0A15D3977816"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s5248f-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76D65A3E-C2D1-4E49-806C-64EF32FDD240"
            },
            {
              "criteria": "cpe:2.3:h:dell:emc_powerswitch_s5296f-on:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AA90B3A-9E44-401B-8BE9-83B0AE2F160B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}