Synology has released a security update for the Synology SSL VPN Client utility to address vulnerabilities: CVE-2021-47960 allows remote attackers to access sensitive files from the SSL VPN Client installation directory via a local HTTP service when a user interacts with a crafted web page. CVE-2021-47961 allows remote attackers to obtain or manipulate the PIN code in SSL VPN Client, potentially leading to unauthorized VPN configuration and traffic interception when a user interacts with a crafted web page. Please refer to the Affected Products table for the corresponding updates.
Continue reading...
- - -
Synology Product Security Advisory: check the list
Source: synology.com
Continue reading...
- - -
Synology Product Security Advisory: check the list
Source: synology.com