Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-28799


An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .


Published

2021-05-13T03:15:06.843

Last Modified

2025-03-12T20:57:59.413

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-285
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qnap hybrid_backup_sync < 16.0.0415 Yes
Application qnap qts 4.5.2 No
Application qnap hybrid_backup_sync < 3.0.210412 Yes
Operating System qnap qts 4.3.6 No
Application qnap hybrid_backup_sync < 3.0.210411 Yes
Application qnap qts 4.3.3 No
Application qnap qts 4.3.4 No
Application qnap hybrid_backup_sync < 16.0.0419 Yes
Operating System qnap quts_hero h4.5.1 No
Application qnap hybrid_backup_sync < 16.0.0419 Yes
Operating System qnap qutscloud ≤ c4.5.4 No

References