QSearchQSearch

CVE-2021-47961

8.1 HIGH

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influen...

Published: 2026-04-10 · Last updated: 2026-05-29

Severity and scoring

CVSS
8.1 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CWE
CWE-256

Affected products

VendorProduct
synologyssl_vpn_client

Description

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2024-47273 An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology ... (4.3 MEDIUM)
  • CVE-2024-47263 An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in ... (4.1 MEDIUM)
  • CVE-2023-52951 A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle... (5.9 MEDIUM)
  • CVE-2022-49042 An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before... (7.8 HIGH)
  • CVE-2022-49036 An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business... (7.8 HIGH)

Same CWE

  • CVE-2024-45636 IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user (4.1 MEDIUM)
  • CVE-2026-36174 GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console (4.6 MEDIUM)
  • CVE-2018-25396 Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administra... (7.5 HIGH)
  • CVE-2025-15624 Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd (7.5 HIGH)
  • CVE-2025-15128 A vulnerability was detected in ZKTeco BioTime up to 9.0.3/9.0.4/9.5.2 (5.3 MEDIUM)