CVE-2024-53702

EUVD-2024-52035
Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.
PRNG
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA-ADPADP
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
Affected Products (NVD)
VendorProductVersion
sonicwallsma_200_firmware
𝑥
< 10.2.1.14-75sv
sonicwallsma_210_firmware
𝑥
< 10.2.1.14-75sv
sonicwallsma_400_firmware
𝑥
< 10.2.1.14-75sv
sonicwallsma_410_firmware
𝑥
< 10.2.1.14-75sv
sonicwallsma_500v_firmware
𝑥
< 10.2.1.14-75sv
𝑥
= Vulnerable software versions