A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.
Metrics
Affected Vendors & Products
References
History
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Plaintext Password Storage in Synology SSL VPN Client Enabling Unauthorized VPN Configuration |
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology
Synology ssl Vpn Client |
|
| Vendors & Products |
Synology
Synology ssl Vpn Client |
Fri, 10 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction. | |
| Weaknesses | CWE-256 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: synology
Published: 2026-04-10T09:22:37.522Z
Updated: 2026-04-10T12:42:56.656Z
Reserved: 2026-04-10T06:29:38.695Z
Link: CVE-2021-47961
Updated: 2026-04-10T12:42:53.753Z
Status : Awaiting Analysis
Published: 2026-04-10T10:16:03.913
Modified: 2026-04-13T15:02:06.187
Link: CVE-2021-47961
No data.