Files Exposure Vulnerability in Synology SSL VPN Client
CVE-2021-47960
6.5MEDIUM
What is CVE-2021-47960?
A vulnerability in Synology SSL VPN Client prior to version 1.4.5-0684 permits remote attackers to exploit files and directories through a local HTTP server connected to the loopback interface. By tricking users into interacting with a malicious web page, attackers may gain access to sensitive information such as configuration files, certificates, and logs, potentially compromising data integrity and confidentiality.
Affected Version(s)
Synology SSL VPN Client *
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Laurent Sibilla (https://www.linkedin.com/in/lsibilla/)