VPN Security Alert: Synology Patches Flaws in SSL VPN Client
ID: e1542ace-8a34-573d-be0d-1da5464734a2
STIX ID: report--e1542ace-8a34-573d-be0d-1da5464734a2
Feed Name: securityonline.info
Threat Score
Synology issued an urgent security update for SSL VPN Client to fix two Important vulnerabilities: CVE-2021-47960 (CVSS 6.5) allowing local-loopback access to installation files and information disclosure, and CVE-2021-47961 (CVSS 8.1) resulting from plaintext password storage that can enable PIN manipulation, unauthorized VPN configuration, and traffic interception; users must upgrade to version 1.4.5-0684 or later as there are no known workarounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
