PT-2024-9234 · Sonicwall · Sonicwall Sma100

Alain Mowat

·

Published

2024-12-03

·

Updated

2024-12-06

·

CVE-2024-53702

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: SonicWall SMA100 series (affected versions not specified)
Description: The issue is related to the use of a cryptographically weak pseudo-random number generator (PRNG) in the SonicWall SMA100 SSLVPN backup code generator. This weakness can be exploited by a remote attacker to potentially expose protected information. The PRNG's predictability in certain cases allows an attacker to possibly uncover the generated secret.
Recommendations: For SonicWall SMA100 series, consider disabling the use of the PRNG in the SSLVPN backup code generator until a patch or fix is available. As a temporary workaround, restrict access to the SSLVPN backup code generator to minimize the risk of exploitation. Avoid using the SSLVPN backup code generator until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-10922
CVE-2024-53702

Affected Products

Sonicwall Sma100