CVE-2021-47961Disclosure(synology / ssl_vpn_client)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch synology ssl_vpn_client systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-256

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ssl_vpn_client

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 1 mentions (2026-04-10); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
ssl_vpn_client

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Mentions · 2026-04-20: 1Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 104-1004-1204-1304-2004-21
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-101
Disclosure1
2026-04-121
Disclosure1
2026-04-131
Disclosure1
2026-04-201
Patch1
2026-04-211
Patch1
Full discourse5 posts
  • Autumn Good@autumn_good_35
    Disclosure

    『CVE-2021-47961 allows remote attackers to obtain or manipulate the PIN code in SSL VPN Client,』 CVE-2021-47960 CVE-2021-47961 Synology-SA-26:05 Synology SSL VPN Client https://www.synology.com/en-global/security/advisory/Synology_SA_26_05

    Post summary

    The advisory identifies CVE-2021-47961 as a vulnerability that lets remote attackers manipulate PIN codes in Synology SSL VPN Client; no PoC, exploit, or active exploitation details are present.

    00020577
    6.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Synology SSL VPN Client の脆弱性 CVE-2021-47960/47961 が FIX:機密データ漏洩の恐れ https://iototsecnews.jp/2026/04/14/synology-ssl-vpn-client-vulnerability-enabled-remote-access-to-sensitive-files/ これらの脆弱性の原因は、プログラムの基本的な設計や管理の不備にあります。脆弱性 CVE-2021-47960 では、インストールしたフォルダのアクセス権限が適切に設定されず、リモートから内部情報が読み取れる状態になっていました。また、脆弱性 CVE-2021-47961 では、本来は厳重に保護されるべき機密情報が、平文 (プレーンテキスト) 形式で保存されていたことが大きな要因です。ご利用のチームは、ご注意ください。 #CVE202147960 #CVE202147961 #SSLVPNClient #Synology #Vulnerability

    Post summary

    The post reports that Synology SSL VPN Client vulnerabilities CVE-2021-47960 and CVE-2021-47961 have been fixed, detailing how improper access controls and plaintext storage enabled sensitive data leakage.

    01000136
    486 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2021-47961 (CVSS 8.1) Synology SSL VPN Client <1.4.5-0684 stores passwords in plaintext, enabling remote attackers to access PIN codes & intercept VPN traffic. Patch immediately. #CVE #PatchNow https://t.co/2Yxx3a8nEv

    Post summary

    Older Synology SSL VPN Client versions store passwords in plaintext, creating a high‑severity risk (CVE‑2021‑47961); users should apply the patch immediately to mitigate the vulnerability.

    0000057
    26 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2021-47961 📊 Severity: 8.1 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2021-47961 #CVE-2021-47961 #CVE #High #CyberSecurity #InfoSec https://t.co/PWGOEY9Qu9

    Post summary

    The tweet announces CVE‑2021‑47961, notes its high severity and risk level, and directs readers to the NVD for details.

    0000042
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2021-47961 A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to… https://www.cve.org/CVERecord?id=CVE-2021-47961

    Post summary

    The note discloses that Synology SSL VPN Client versions prior to 1.4.5‑0684 store passwords in plaintext, letting remote attackers read or alter a user’s PIN code; no exploit, patch, or active‑exploitation info is included.

    0000076
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsynologyssl_vpn_client---

Explore more