Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jcx-2m59-6cv8

Опубликовано: 10 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.

EPSS

Процентиль: 25%
0.00322
Низкий

8.1 High

CVSS3

Дефекты

CWE-256

Связанные уязвимости

CVSS3: 8.1
nvd
4 месяца назад

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user interaction.

CVSS3: 8.1
fstec
4 месяца назад

Уязвимость VPN-клиента Synology SSL VPN Client, связанная с хранением паролей в незашифрованном виде, позволяющая нарушителю перехватить VPN-трафик при взаимодействии с пользователем

EPSS

Процентиль: 25%
0.00322
Низкий

8.1 High

CVSS3

Дефекты

CWE-256