CRITICAL

CVE-2021-28799

Qnap Hybrid Backup Sync 2021-05-13 CVSS v3.1
CVSS
9.8
KEV

Description

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

Summary dbcve.org

An improper authorization vulnerability in QNAP HBS 3 (Hybrid Backup Sync) allows remote attackers to bypass authentication and log in to affected NAS devices. This is an authentication bypass flaw in the HBS 3 application affecting multiple QTS and QuTS firmware versions.

Mitigation

Update HBS 3 to the patched versions: v16.0.0415 or later for QTS 4.5.2, v3.0.210412 or later for QTS 4.3.6, v3.0.210411 or later for QTS 4.3.4/4.3.3, and v16.0.0419 or later for QuTS hero h4.5.1 and QuTScloud c4.5.1-c4.5.4.

Weakness (CWE)

CWE-285 Improper Authorization

EPSS Score

78.25%
Probability of exploitation in next 30 days
99.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE