CVE-2018-8929: Synology SSL VPN Client

High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.

Affected products

  • Synology SSL VPN Client: before 1.2.4-0224 (fixed in 1.2.4-0224)

Published 2018-07-06. Last modified 2026-06-17.