Critical Synology SSL VPN Client Flaw Lets Remote Attackers Access Sensitive Files
ID: 8affe916-b202-54d0-9555-b8d5fe3e4cec
STIX ID: report--8affe916-b202-54d0-9555-b8d5fe3e4cec
Feed Name: Cyber Press
Synology released an urgent advisory (Synology-SA-26:05) fixing two vulnerabilities in its SSL VPN Client: CVE-2021-47960 (improper installation permissions allowing local files to be read via a loopback HTTP server) and CVE-2021-47961 (user passwords stored in plaintext). Both issues can be exploited through social engineering (malicious web pages/links), may expose configuration, logs, certificates and authentication tokens, and could let attackers monitor or manipulate VPN traffic; Synology urges immediate update to version 1.4.5-0684 with no alternative mitigations available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
