Improper Communication Channel Restriction in Synology SSL VPN Client
CVE-2018-8929
7.3HIGH
What is CVE-2018-8929?
The Synology SSL VPN Client is susceptible to an improper restriction of the communication channel vulnerability, allowing remote attackers to exploit this flaw. By crafting a specific payload, an attacker can execute man-in-the-middle attacks, intercepting and potentially modifying traffic between the user and intended endpoints. This poses significant risks to the confidentiality and integrity of sensitive information transmitted through the VPN.
Affected Version(s)
SSL VPN Client < 1.2.4-0224