VDB
CVE-2021-47961
CVE-2021-47961
PUBLISHED
CVSS 8.1 HIGH
Reported by synology · Published April 10, 2026
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.
EPSS 0.05% · 15.4th percentile
Risk Scores
CVSS 3.1
8.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score
0.05%
15.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Synology | Synology SSL VPN Client | * |
| Synology | Synology SSL VPN Client | * |
Timeline
- Apr 10, 2026 CVE Published
- Apr 10, 2026 PoC Published
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score
References
- Synology-SA-26:05 Synology SSL VPN Client vendor-advisory