peter bassill · operator
$ cve CVE-2021-28799 JSON

CVE-2021-28799 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 78.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-21.

Description

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS78.25% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-285
On CISA KEVyes — remediate by 2022-04-21
Public exploitnone known
Published2021-05-13
Last modified2026-06-17

CISA KEV

NameQNAP NAS Improper Authorization Vulnerability
Added2022-03-31
Due2022-04-21
Vendor / productQNAP / Network Attached Storage (NAS)
Ransomware useknown

Affected (4)

VendorProduct
qnaphybrid backup sync
qnapqts
qnapquts hero
qnapqutscloud

References

→ the Explorer  ·  watch your stack  ·  NVD