CVE-2024-53702
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.2.1.14-75sv |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma 200 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.2.1.14-75sv |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma 210 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.2.1.14-75sv |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma 400 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.2.1.14-75sv |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma 410 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.2.1.14-75sv |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma 500v | All versions |
References (1)
Source: PSIRT@sonicwall.com
Vendor Advisory
Timeline
No history available yet.