A files or directories accessible to external parties vulnerability in...
Vulnerability Description
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may retrieve sensitive files such as configuration files, certificates, and logs, leading to information disclosure.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47960
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Laurent Sibilla (https://www.linkedin.com/in/lsibilla/)
More from Synology
View All →Affected Vendor
Synology
View all reports →