Synology SSL VPN Client
cpe:2.3:a:synology:ssl_vpn_client:*:*:*:*:*:*:*
- < 1.4.5-0684
A vulnerability allowing plaintext storage of passwords has been identified in Synology SSL VPN Client versions prior to 1.4.5-0684. This vulnerability enables remote attackers to access or manipulate the user's PIN code due to insecure storage practices. The issue could lead to unauthorized VPN configuration and interception of VPN traffic, particularly when combined with user interaction.
Exploitation of this vulnerability could result in unauthorized access to or manipulation of VPN configuration, allowing interception of VPN traffic.
Users are advised to upgrade to Synology SSL VPN Client version 1.4.5-0684 or above.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.