Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-28809


An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later


Published

2021-07-08T08:15:07.663

Last Modified

2024-11-21T06:00:14.603

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-284
    CWE-306
    CWE-749

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qnap hybrid_backup_sync < 3.0.210507 Yes
Operating System qnap qts 4.3.6 No
Application qnap hybrid_backup_sync < 3.0.210506 Yes
Operating System qnap qts 4.3.4 No
Application qnap hybrid_backup_sync < 3.0.210506 Yes
Operating System qnap qts 4.3.3 No

References