CVE-2021-47960: Medium severity Synology Synology SSL VPN Client vulnerability
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47960?
CVE-2021-47960 has been classified as a high-severity vulnerability due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2021-47960?
To mitigate CVE-2021-47960, update the Synology SSL VPN Client to version 1.4.5-0684 or later.
What type of vulnerability is CVE-2021-47960?
CVE-2021-47960 is a files or directories accessible to external parties vulnerability.
What can attackers do with CVE-2021-47960?
Attackers can access files within the installation directory of the Synology SSL VPN Client if users interact with a malicious web page.
Is my system affected by CVE-2021-47960?
If you are using Synology SSL VPN Client versions prior to 1.4.5-0684, your system is affected by CVE-2021-47960.