PT-2025-1011 · Sonicwall · Sonicos+1

Published

2025-01-07

·

Updated

2025-01-10

·

CVE-2024-40762

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SonicOS (affected versions not specified) SonicWALL NSv (affected versions not specified)
Description: The issue is related to the use of a cryptographically weak pseudo-random number generator (PRNG) in the SonicOS SSLVPN authentication token generator. This weakness can potentially be exploited by an attacker to predict the authentication token, resulting in an authentication bypass. The vulnerability is associated with the implementation of SSL VPN technology in SonicOS and can allow a remote attacker to gain unauthorized access to protected information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00206
CVE-2024-40762
ZDI-25-011

Affected Products

Sonicos
Sonicwall Nsv