CVE-2021-47961
8.1 HIGHA plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influen...
Published: 2026-04-10 · Last updated: 2026-05-29
Severity and scoring
- CVSS
- 8.1 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- CWE
- CWE-256
Affected products
| Vendor | Product |
|---|---|
| synology | ssl_vpn_client |
Description
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2024-47273 — An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology ... (4.3 MEDIUM)
- CVE-2024-47263 — An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in ... (4.1 MEDIUM)
- CVE-2023-52951 — A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle... (5.9 MEDIUM)
- CVE-2022-49042 — An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before... (7.8 HIGH)
- CVE-2022-49036 — An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business... (7.8 HIGH)
Same CWE
- CVE-2024-45636 — IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user (4.1 MEDIUM)
- CVE-2026-36174 — GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console (4.6 MEDIUM)
- CVE-2018-25396 — Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administra... (7.5 HIGH)
- CVE-2025-15624 — Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd (7.5 HIGH)
- CVE-2025-15128 — A vulnerability was detected in ZKTeco BioTime up to 9.0.3/9.0.4/9.5.2 (5.3 MEDIUM)