First published: Thu Jul 08 2021(Updated: )
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP NAS | <3.0.210507 | |
QNAP QTS | =4.3.6 | |
QNAP NAS | <3.0.210506 | |
QNAP QTS | =4.3.4 | |
QNAP QTS | =4.3.3 | |
QNAP NAS |
QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28809 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of QNAP NAS.
CVE-2021-28809 has a severity score of 9.8, which is classified as critical.
The affected software for CVE-2021-28809 includes QNAP NAS with Hybrid Backup Sync up to version 3.0.210507.
No, QNAP QTS versions 4.3.6, 4.3.4, and 4.3.3 are not vulnerable to CVE-2021-28809.
To fix CVE-2021-28809, users should update their QNAP NAS Hybrid Backup Sync to version 3.0.210507 or later.