CVE-2024-40762

CRITICAL

SonicOS - Auth Bypass

Title source: llm
STIX 2.1

Description

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.

Scores

CVSS v3 9.8
EPSS 0.0004
EPSS Percentile 12.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-338
Status published
Products (3)
SonicWall/SonicOS 7.1.1-7058 and older versions
SonicWall/SonicOS 7.1.2-7019
SonicWall/SonicOS 8.0.0-8035
Published Jan 09, 2025
Tracked Since Feb 18, 2026