CVE-2024-53702

MEDIUM

SonicWall SMA 200/210/400/410/500v < 10.2.1.14-75sv - Weak PRNG in SSLVPN Backup Code

Title source: llm
STIX 2.1

Description

Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0033
EPSS Percentile 25.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-338
Status published
Products (5)
sonicwall/sma_200_firmware < 10.2.1.14-75sv
sonicwall/sma_210_firmware < 10.2.1.14-75sv
sonicwall/sma_400_firmware < 10.2.1.14-75sv
sonicwall/sma_410_firmware < 10.2.1.14-75sv
sonicwall/sma_500v_firmware < 10.2.1.14-75sv
Published Dec 05, 2024
Tracked Since Feb 18, 2026