CVE-2021-28809
published 2021-07-08CVE-2021-28809: An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
15.80%
96.5th percentile
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qnap | hybrid_backup_sync | < 3.0.210507 | 3.0.210507 |
| qnap | hybrid_backup_sync | < 3.0.210506 | 3.0.210506 |
| qnap_systems_inc | hbs_3 | >= unspecified < v3.0.210507 | v3.0.210507 |
| qnap_systems_inc | hbs_3 | >= unspecified < v3.0.210506 | v3.0.210506 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2021-28809 affects QNAP HBS 3 on legacy QTS versions; exploitation allows privilege escalation, remote command execution, or unauthorized access to sensitive information on NAS devices without authentication ↗
- ·Vulnerability only affects legacy HBS 3 versions on QTS 4.3.6 (prior to v3.0.210507), QTS 4.3.4 (prior to v3.0.210506), and QTS 4.3.3 (prior to v3.0.210506); newer QTS versions are not affected ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2021-07-08
Published