216.73.216.233

CVE-2024-40762

· Published 09/01/2025 07:15 · Modified 09/01/2025 15:15

Labels: CVE-2024-40762 2025-01-09CVE-2024-40762CWE-338[email protected]

Essential information

Published
09/01/2025 07:15
Modified
09/01/2025 15:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References