Unprotected storage of credentials in SSL VPN Client - CVE-2021-47961

 

Unprotected storage of credentials in SSL VPN Client - CVE-2021-47961

Published: April 14, 2026


Vulnerability identifier: #VU125952
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-47961
CWE-ID: CWE-256
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain or manipulate the PIN code, potentially leading to unauthorized VPN configuration and traffic interception.

The vulnerability exists due to plaintext storage of a password in PIN code storage when a user interacts with a crafted web page. A remote attacker can trick the victim into interacting with a crafted web page to obtain or manipulate the PIN code, potentially leading to unauthorized VPN configuration and traffic interception.

User interaction is required.


Affected software

SSL VPN Client

How to mitigate CVE-2021-47961

Install security update from vendor's website.

SSL VPN Client - update to 1.4.5-0684

External References

Related Security Bulletins