CVE-2024-53702

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/12/2024
Last modified:
04/11/2025

Description

Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:* 10.2.1.14-75sv (excluding)
cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:* 10.2.1.14-75sv (excluding)
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:* 10.2.1.14-75sv (excluding)
cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:* 10.2.1.14-75sv (excluding)
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:* 10.2.1.14-75sv (excluding)
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools