CVE-2024-40762: SonicWall SonicOS

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator that, in certain cases, can be predicted by an attacker potentially resulting in authentication bypass.

Affected products

  • SonicWall SonicOS: up to and including 7.1.1-7058; version 7.1.2-7019 only; version 8.0.0-8035 only

Published 2025-01-09. Last modified 2026-06-17.