CVE-2021-28799: QNAP NAS Improper Authorization Vulnerability
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
Other sources
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QNAP HBS 3 on QTS 4.3.3to a version that resolves this vulnerability.Fixed in v3.0.210411 - Upgrade
Upgrade
QNAP HBS 3 on QTS 4.3.4to a version that resolves this vulnerability.Fixed in v3.0.210411 - Upgrade
Upgrade
QNAP HBS 3 on QTS 4.3.6to a version that resolves this vulnerability.Fixed in v3.0.210412 - Upgrade
Upgrade
QNAP HBS 3 on QTS 4.5.2to a version that resolves this vulnerability.Fixed in v16.0.0415 - Upgrade
Upgrade
QNAP HBS 3 on QuTS hero h4.5.1to a version that resolves this vulnerability.Fixed in v16.0.0419 - Upgrade
Upgrade
QNAP HBS 3 on QuTScloud c4.5.1~c4.5.4to a version that resolves this vulnerability.Fixed in v16.0.0419
Event History
Frequently Asked Questions
What is CVE-2021-28799?
CVE-2021-28799 is an improper authorization vulnerability affecting QNAP NAS running HBS 3 (Hybrid Backup Sync).
How does CVE-2021-28799 impact QNAP NAS?
If exploited, CVE-2021-28799 allows remote attackers to log in to a device.
Which versions of QNAP HBS 3 are affected by CVE-2021-28799?
CVE-2021-28799 affects QNAP HBS 3 versions prior to v16.0.0415.
Are the QNAP QTS versions vulnerable to CVE-2021-28799 as well?
QNAP QTS versions are not vulnerable to CVE-2021-28799.
How severe is CVE-2021-28799?
CVE-2021-28799 has a severity rating of 9.8 (critical).