Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-47961

29
FAUCET Score

CVE-2021-47961 is a plaintext password storage vulnerability affecting Synology SSL VPN Client versions prior to 1.4.5-0684, where PIN codes and credentials are insecurely stored, allowing remote attackers to recover authentication secrets. This weakness becomes particularly dangerous when combined with user interaction, potentially enabling unauthorized VPN configuration changes and interception of subsequent VPN traffic. The vulnerability carries a HIGH severity rating (CVSS 8.1) with a network-based attack vector requiring minimal complexity and low user interaction to exploit. While it does not enable denial of service, the attack successfully compromises both confidentiality and integrity of VPN configurations, representing a significant risk to users relying on this client for secure remote access. There is currently no evidence of active exploitation in the wild, as the vulnerability does not appear on CISA's Known Exploited Vulnerabilities list. The EPSS score of 0.00044 suggests low near-term exploitation probability, and community attention remains limited. However, organizations using affected Synology SSL VPN Client versions should prioritize upgrading to version 1.4.5-0684 or later to eliminate this plaintext credential storage weakness.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.4.5-0684CPE matchmatch criteria
cpe:2.3:a:synology:ssl_vpn_client:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 29th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

synology.com / en-global/security/advisory/Synology_SA_26_05
Vendor Advisory