PT-2026-31905 · Synology · Synology Ssl Vpn Client
Laurent Sibilla
·
Published
2026-04-10
·
Updated
2026-04-10
·
CVE-2021-47960
CVSS v3.1
6.5
Medium
| AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure.
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Synology Ssl Vpn Client