VYPR

SSL VPN Client

by Synology

CVEs (5)

  • CVE-2018-13283HigApr 1, 2019
    risk 0.57cvss 8.8epss 0.01

    Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers to conduct man-in-the-middle attacks via the (1) command, (2) hostname, or (3) port parameter.

  • CVE-2021-47961HigApr 10, 2026
    risk 0.53cvss 8.1epss 0.00

    A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN…

  • CVE-2018-8929HigJul 6, 2018
    risk 0.48cvss 7.3epss 0.01

    Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.

  • CVE-2021-47960MedApr 10, 2026
    risk 0.42cvss 6.5epss 0.00

    A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with…

  • CVE-2023-5748LowNov 7, 2023
    risk 0.21cvss 3.3epss 0.00

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 allows local users to conduct denial-of-service attacks via unspecified vectors.