CVE-2021-47961
- EPSS 0.05%
- Veröffentlicht 10.04.2026 10:16:03
- Zuletzt bearbeitet 13.04.2026 15:02:06
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential int...
CVE-2021-47960
- EPSS 0.03%
- Veröffentlicht 10.04.2026 10:16:02
- Zuletzt bearbeitet 13.04.2026 15:02:06
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By lev...
CVE-2023-5748
- EPSS 0.09%
- Veröffentlicht 07.11.2023 04:24:19
- Zuletzt bearbeitet 21.11.2024 08:42:24
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 allows local users to conduct denial-of-service attacks via unspecified vectors.
CVE-2018-13283
- EPSS 0.22%
- Veröffentlicht 01.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:45
Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers to conduct man-in-the-middle attacks via the (1) command, (2) hostname, or (3) port parameter.
CVE-2018-8929
- EPSS 0.18%
- Veröffentlicht 06.07.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:37
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.