CVE-2024-53702

MEDIUM

SonicWall SMA100 - Info Disclosure

Title source: llm

Description

Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.

Scores

CVSS v3 5.3
EPSS 0.0027
EPSS Percentile 50.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-338
Status published

Affected Products (5)

sonicwall/sma_200_firmware < 10.2.1.14-75sv
sonicwall/sma_210_firmware < 10.2.1.14-75sv
sonicwall/sma_400_firmware < 10.2.1.14-75sv
sonicwall/sma_410_firmware < 10.2.1.14-75sv
sonicwall/sma_500v_firmware < 10.2.1.14-75sv

Timeline

Published Dec 05, 2024
Tracked Since Feb 18, 2026