VDB

CVE-2021-47961

CVE-2021-47961 PUBLISHED CVSS 8.1 HIGH

Reported by synology · Published April 10, 2026

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.

EPSS 0.05% · 15.4th percentile

Risk Scores

CVSS 3.1
8.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score
0.05%
15.4th percentile

Affected Products

VendorProductVersions
SynologySynology SSL VPN Client*
SynologySynology SSL VPN Client*

Timeline

  • Apr 10, 2026 CVE Published
  • Apr 10, 2026 PoC Published
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›