CVE-2021-47961 is a plaintext password storage vulnerability affecting Synology SSL VPN Client versions prior to 1.4.5-0684, where PIN codes and credentials are insecurely stored, allowing remote attackers to recover authentication secrets. This weakness becomes particularly dangerous when combined with user interaction, potentially enabling unauthorized VPN configuration changes and interception of subsequent VPN traffic. The vulnerability carries a HIGH severity rating (CVSS 8.1) with a network-based attack vector requiring minimal complexity and low user interaction to exploit. While it does not enable denial of service, the attack successfully compromises both confidentiality and integrity of VPN configurations, representing a significant risk to users relying on this client for secure remote access. There is currently no evidence of active exploitation in the wild, as the vulnerability does not appear on CISA's Known Exploited Vulnerabilities list. The EPSS score of 0.00044 suggests low near-term exploitation probability, and community attention remains limited. However, organizations using affected Synology SSL VPN Client versions should prioritize upgrading to version 1.4.5-0684 or later to eliminate this plaintext credential storage weakness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.5-0684CPE matchmatch criteria | cpe:2.3:a:synology:ssl_vpn_client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.