SonicWall SonicOS
cpe:2.3:o:dell:sonicwall_sonicos:*:*:*:*:*:*:*, +2 more
- >= 7.1, <= 7.1.1-7058
- >= 7.1.2-7019
A vulnerability exists in the SonicOS SSLVPN authentication token generator due to the use of a cryptographically weak pseudo-random number generator (PRNG). In certain cases, this weakness allows an attacker to predict the generated tokens, potentially leading to authentication bypass. This issue affects multiple versions of SonicWall SonicOS on both Gen6 and Gen7 firewalls, as well as the Gen7 Cloud platform NSv (AWS and Azure editions only)
Exploitation of this vulnerability can lead to authentication bypass, allowing unauthorized access to users or systems
Users are advised to update to the latest patched versions of SonicWall SonicOS. The latest patch builds are available for download on mysonicwall.com. If an immediate update is not possible, disable SSLVPN access from the Internet. For more information on how to disable SSLVPN access, consult the SonicWall knowledge base.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.