CVE-2021-47960
Analyzed Analyzed - Analysis Complete
Information Disclosure via Local HTTP Server in Synology SSL VPN Client

Publication date: 2026-04-10

Last updated on: 2026-05-29

Assigner: Synology Inc.

Description
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-10
Last Modified
2026-05-29
Generated
2026-06-16
AI Q&A
2026-04-10
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
synology ssl_vpn_client to 1.4.5-0684 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-552 The product makes files or directories accessible to unauthorized actors, even though they should not be.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2021-47960 is a vulnerability in the Synology SSL VPN Client versions before 1.4.5-0684 that allows remote attackers to access files within the installation directory.

This is possible because the client runs a local HTTP server bound to the loopback interface, which can be exploited by an attacker who tricks the user into interacting with a crafted web page.

By doing so, the attacker can retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure.

Impact Analysis

This vulnerability can lead to the disclosure of sensitive information stored within the Synology SSL VPN Client installation directory.

  • Attackers may gain access to configuration files, certificates, and logs.
  • Such information disclosure could compromise the security of the VPN connection and potentially expose private data.

Exploitation requires user interaction, specifically visiting a crafted web page.

Mitigation Strategies

The only mitigation provided for this vulnerability is to upgrade the Synology SSL VPN Client to version 1.4.5-0684 or later.

No other mitigations or workarounds are mentioned.

Compliance Impact

The vulnerability in Synology SSL VPN Client allows remote attackers to access sensitive files such as configuration files, certificates, and logs, leading to information disclosure.

Such unauthorized disclosure of sensitive information could potentially impact compliance with data protection standards and regulations like GDPR and HIPAA, which require safeguarding sensitive data against unauthorized access.

However, the provided information does not explicitly state the direct impact on compliance with these standards or any regulatory consequences.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2021-47960. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart