Vulnerabilities > Synology > SSL VPN Client

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2023-5748 Classic Buffer Overflow vulnerability in Synology SSL VPN Client
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 allows local users to conduct denial-of-service attacks via unspecified vectors.
local
low complexity
synology CWE-120
5.5
2019-04-01 CVE-2018-13283 Unspecified vulnerability in Synology SSL VPN Client
Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers to conduct man-in-the-middle attacks via the (1) command, (2) hostname, or (3) port parameter.
network
high complexity
synology
7.4
2018-07-06 CVE-2018-8929 Channel and Path Errors vulnerability in Synology SSL VPN Client
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.
network
high complexity
synology CWE-417
8.1