CVE-2024-53702

Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.
PRNG
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
sonicwallCNA
---
---
CISA-ADPADP
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
VendorProductVersion
sonicwallsma_200_firmware
𝑥
< 10.2.1.14-75sv
sonicwallsma_210_firmware
𝑥
< 10.2.1.14-75sv
sonicwallsma_400_firmware
𝑥
< 10.2.1.14-75sv
sonicwallsma_410_firmware
𝑥
< 10.2.1.14-75sv
sonicwallsma_500v_firmware
𝑥
< 10.2.1.14-75sv
𝑥
= Vulnerable software versions