CVE-2021-47961
8.1Synology · SSL VPN Client
Synology SSL VPN Client stores passwords in plaintext, potentially allowing remote attackers to access user PINs and compromise VPN configurations.
Executive summary
A plaintext password storage vulnerability in the Synology SSL VPN Client exposes user credentials and risks unauthorized VPN configuration access.
Vulnerability
This vulnerability involves the insecure storage of credentials (CWE-256) within the client software. An attacker can leverage this flaw to access or influence user PIN codes, which may facilitate unauthorized VPN configuration changes or the interception of VPN traffic when combined with user interaction.
Business impact
The exploitation of this vulnerability could lead to significant security breaches, including the unauthorized access to private network resources via the VPN. With a CVSS score of 8.1, this represents a high-severity risk that could result in the compromise of sensitive corporate data, unauthorized lateral movement, and the potential for long-term credential theft.
Remediation
Immediate Action: Update the Synology SSL VPN Client to version 1.4.5-0684 or later as specified in the official vendor advisory.
Proactive Monitoring: Review VPN access logs for anomalous login patterns or unauthorized configuration changes that do not correspond to known user behavior.
Compensating Controls: Ensure that multi-factor authentication (MFA) is enforced for all VPN connections to mitigate the impact of potentially compromised credentials.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the nature of VPN access as a primary gateway to internal networks, organizations should prioritize updating the Synology SSL VPN Client. Failure to patch these endpoints leaves remote access infrastructure vulnerable to credential harvesting and subsequent unauthorized entry.
More Synology CVEs
Sources
Originally found and disclosed by Laurent Sibilla (https://www.linkedin.com/in/lsibilla/), per the CVE Program record.
- Synology-SA-26:05 Synology SSL VPN Client Vendor advisory