A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.
References
| Link | Resource |
|---|---|
| https://www.synology.com/en-global/security/advisory/Synology_SA_26_05 | Vendor Advisory |
Configurations
History
29 May 2026, 19:05
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.synology.com/en-global/security/advisory/Synology_SA_26_05 - Vendor Advisory | |
| CPE | cpe:2.3:a:synology:ssl_vpn_client:*:*:*:*:*:*:*:* | |
| First Time |
Synology
Synology ssl Vpn Client |
10 Apr 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-10 10:16
Updated : 2026-05-29 19:05
NVD link : CVE-2021-47961
Mitre link : CVE-2021-47961
CVE.ORG link : CVE-2021-47961
JSON object : View
Products Affected
synology
- ssl_vpn_client
CWE
CWE-256
Plaintext Storage of a Password
