Junglewise Threat Intelligence

CVE-2021-28799: QNAP NAS Improper Authorization Vulnerability

CVE-2021-28799 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-31

Technologies: QNAP Network Attached Storage (NAS). Vendors: QNAP, QNAP Systems, Inc..

Executive brief

An improper authorization vulnerability in QNAP NAS devices running HBS 3 (Hybrid Backup Sync) allows remote attackers to log in to the device without proper credentials. This vulnerability has been observed being exploited in the wild.

Affected products

  • QNAP Systems Inc. HBS 3 (Hybrid Backup Sync) prior to v16.0.0415 on QTS 4.5.2; prior to v3.0.210412 on QTS 4.3.6; prior to v3.0.210411 on QTS 4.3.4; prior to v3.0.210411 on QTS 4.3.3; prior to v16.0.0419 on QuTS hero h4.5.1; prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4

Timeline

  • 2021-04-16: patched: Vendor released patches for various OS versions (based on version strings like 210412)
  • 2022-03-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-31: disclosed: NVD publication date

Related threats