PublicCVE

CVE-2024-53702

MEDIUM5.3JSON exportCreate alert

Description

Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certain cases, can be predicted by an attacker, potentially exposing the generated secret.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected products

  • SonicWall / SMA10010.2.1.13-72sv and earlier versions – 10.2.1.13-72sv and earlier versions