VDB
CISA-2024-40762
CISA-2024-40762
PUBLISHED
CVSS 9.8 CRITICAL
Reported by sonicwall · Published January 9, 2025
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.
Risk Scores
CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SonicWall | SonicOS | 7.1.1-7058 and older versions, 7.1.2-7019, 8.0.0-8035 |
| SonicWall | SonicOS | 7.1.2-7019, 7.1.1-7058 and older versions, 8.0.0-8035 |
Timeline
- Jan 9, 2025 CVE Published
- Jan 9, 2025 CVE Updated