Vulnerability Intelligence Report
CVE-2024-40762
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.99%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-338 ↗CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SonicWall | SonicOS | 7.1.1-7058 and older versions (affected), 7.1.2-7019 (affected), 8.0.0-8035 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.994%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SonicWall, Inc. · Vendor · USA |
| Reserved | 2024-07-10T15:58:49 |
| Published | 2025-01-09T06:43:25 |
| Patch Date | 2025-01-08 |
| Last Updated | 2025-01-09T15:08:11 |
Community Chatter & Buzz