← Volver a CVEs
CVE-2024-40762
CRITICAL9.8
Descripcion
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado1/9/2025
Ultima modificacion1/9/2025
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-338
Referencias
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003(PSIRT@sonicwall.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.