CVE-2021-47960Disclosure(synology / ssl_vpn_client)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch synology ssl_vpn_client systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-552

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ssl_vpn_client

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
ssl_vpn_client

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-21: 104-1004-1204-1304-21
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Autumn Good@autumn_good_35
    Disclosure

    『CVE-2021-47961 allows remote attackers to obtain or manipulate the PIN code in SSL VPN Client,』 CVE-2021-47960 CVE-2021-47961 Synology-SA-26:05 Synology SSL VPN Client https://www.synology.com/en-global/security/advisory/Synology_SA_26_05

    Post summary

    The text announces CVE-2021-47961 for Synology SSL VPN Client, describing its remote PIN manipulation flaw and pointing to a vendor advisory that presumably contains patches or mitigations.

    00020577
    6.9K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Synology SSL VPN Client の脆弱性 CVE-2021-47960/47961 が FIX:機密データ漏洩の恐れ https://iototsecnews.jp/2026/04/14/synology-ssl-vpn-client-vulnerability-enabled-remote-access-to-sensitive-files/ これらの脆弱性の原因は、プログラムの基本的な設計や管理の不備にあります。脆弱性 CVE-2021-47960 では、インストールしたフォルダのアクセス権限が適切に設定されず、リモートから内部情報が読み取れる状態になっていました。また、脆弱性 CVE-2021-47961 では、本来は厳重に保護されるべき機密情報が、平文 (プレーンテキスト) 形式で保存されていたことが大きな要因です。ご利用のチームは、ご注意ください。 #CVE202147960 #CVE202147961 #SSLVPNClient #Synology #Vulnerability

    Post summary

    The post discloses Synology SSL VPN Client vulnerabilities CVE‑2021‑47960 and CVE‑2021‑47961, detailing permission and storage flaws, but provides no PoC, exploit, active usage, patch, or debunking information.

    01000136
    486 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2021-47960 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2021-47960 #CVE-2021-47960 #CVE #Medium #CyberSecurity #InfoSec https://t.co/1a9Wa63AOJ

    Post summary

    A new CVE (CVE-2021-47960) with medium severity is announced, referencing the NVD entry, with no additional details on exploitation or mitigations.

    0000025
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2021-47960 A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the in… https://www.cve.org/CVERecord?id=CVE-2021-47960

    Post summary

    The text is a brief announcement of CVE‑2021‑47960 highlighting a file‑access flaw in Synology SSL VPN Client; it gives no PoC, exploit, patch, or evidence of active exploitation.

    0000069
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsynologyssl_vpn_client---

Explore more