Files Exposure Vulnerability in Synology SSL VPN Client
CVE-2021-47960

6.5MEDIUM

Key Information:

Vendor

Synology

Vendor
CVE Published:
10 April 2026

What is CVE-2021-47960?

A vulnerability in Synology SSL VPN Client prior to version 1.4.5-0684 permits remote attackers to exploit files and directories through a local HTTP server connected to the loopback interface. By tricking users into interacting with a malicious web page, attackers may gain access to sensitive information such as configuration files, certificates, and logs, potentially compromising data integrity and confidentiality.

Affected Version(s)

Synology SSL VPN Client *

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Laurent Sibilla (https://www.linkedin.com/in/lsibilla/)
.