CVE-2024-40762
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 9, 2025
CWE ID 338
Summary
CVE-2024-40762: This vulnerability affects the SonicOS SSLVPN authentication token generator, which utilizes a cryptographically weak Pseudo-Random Number Generator (PRNG). An attacker can exploit this weakness in specific cases to predict the authentication token and bypass the security measure. This issue poses a potential risk to unauthorized access to SSLVPN-protected systems. Organizations using SonicOS are advised to apply the necessary patches or updates to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.