logo

VPN Security Alert: Synology Patches Flaws in SSL VPN Client

ID: e1542ace-8a34-573d-be0d-1da5464734a2

STIX ID: report--e1542ace-8a34-573d-be0d-1da5464734a2

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Synology issued an urgent security update for SSL VPN Client to fix two Important vulnerabilities: CVE-2021-47960 (CVSS 6.5) allowing local-loopback access to installation files and information disclosure, and CVE-2021-47961 (CVSS 8.1) resulting from plaintext password storage that can enable PIN manipulation, unauthorized VPN configuration, and traffic interception; users must upgrade to version 1.4.5-0684 or later as there are no known workarounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.