CVE-2024-40762

Published Jan 9, 2025

Last updated 2 months ago

Overview

Description
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.
Source
PSIRT@sonicwall.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

PSIRT@sonicwall.com
CWE-338

Social media

Hype score
Not currently trending
  1. Threat Alert: SonicWall tells admins to patch worrying SSLVPN flaw immediately CVE-2024-53704 CVE-2024-40762 CVE-2024-53705 Severity: 🔴 High Maturity: 🧨 Trending Learn more: https://t.co/BE7rIxijE6 #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    10 Jan 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. SonicWALL NSv Cryptographically Weak PRNG Authentication Bypass Vulnerability (CVE-2024-40762) #CVE202440762 #CyberSecurity #SonicWall https://t.co/7IXtCCtdVY

    @SystemTek_UK

    10 Jan 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-53704,CVE-2024-40762,CVE-2024-53705,CVE-2024-53706 alert 🚨 SonicWall improper authentication vulnerability in the SSLVPN The vulnerability is actively exploited in the wild and has been integrated into Patrowl. Our customers assets are protected. 🦉 #CyberSec #SonicWall

    @Patrowl_io

    9 Jan 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2024-40762 Predictable PRNG Weakens SSLVPN Authentication in SonicOS SonicOS SSLVPN has a problem with its authentication token generator. It uses a weak pseudo-random number generator. Sometimes, this weakne... https://t.co/Vj98hrMe6w

    @VulmonFeeds

    9 Jan 2025

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-40762 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by a… https://t.co/mJGG3YFWbX

    @CVEnew

    9 Jan 2025

    177 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨🚨CVE-2024-40762, CVE-2024-53704, CVE-2024-53705, CVE-2024-53706: SonicWall Issues Important Security Advisory for Multiple Vulnerabilities in SonicOS ZoomEye Dork👉banner="SonicOS" 48k+ results are found on ZoomEye. ZoomEye Link: https://t.co/BBGCGDPXCA Refer:… https://t.co

    @zoomeye_team

    8 Jan 2025

    87 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes