CVE-2021-47961

Published Apr 10, 2026

Last updated 9 days ago

Overview

Description
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.
Source
security@synology.com
NVD status
Analyzed
Products
ssl_vpn_client

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Severity
HIGH

Weaknesses

security@synology.com
CWE-256

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.