Files or Directories Accessible to External Parties in SSL VPN Client - CVE-2021-47960

 

Files or Directories Accessible to External Parties in SSL VPN Client - CVE-2021-47960

Published: April 14, 2026


Vulnerability identifier: #VU125951
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-47960
CWE-ID: CWE-552
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Synology Inc.
Affected software:
SSL VPN Client

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to files or directories accessible to external parties in the local HTTP service bound to the loopback interface when handling requests from a crafted web page. A remote attacker can trick the victim into interacting with a crafted web page to disclose sensitive information.

User interaction is required, and exposed files may include configuration files, certificates, and logs from the installation directory.


How to mitigate CVE-2021-47960

Install security update from vendor's website.

Sources