CVE-2020-5349
Description
Hardcoded credential in Dell Networking S4100/S5200 switches allows remote unauthenticated attackers to gain administrative privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Hardcoded credential in Dell Networking S4100/S5200 switches allows remote unauthenticated attackers to gain administrative privileges.
Vulnerability
A hardcoded credential vulnerability exists in Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020. The vulnerability is present in the switch firmware, allowing an attacker to authenticate using a pre-set, unchangeable credential. Affected models include all S4100 and S5200 series switches produced before the specified date [1].
Exploitation
An attacker with network access to the affected switch can exploit the hardcoded credential without any authentication or user interaction. By using the known credential, the attacker can authenticate to the switch management interface and gain administrative-level access [1].
Impact
Successful exploitation grants the attacker full administrative privileges over the switch. This leads to complete compromise of confidentiality, integrity, and availability, as the attacker can read, modify, or disrupt network traffic and device configuration. The CVSS v3.1 base score is 9.8 (Critical) [1].
Mitigation
Dell Technologies recommends that customers with affected switches install a new operating system at the earliest opportunity. No specific fixed version is provided; the mitigation applies to devices manufactured before February 2020. As of the advisory date, no workaround is available other than updating the firmware [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: manufactured prior to February 2020
- Range: S4100 and S5200
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.