CVE-2021-28799

QNAP Network Attached Storage (NAS): NAS Improper Authorization

As of , CVE-2021-28799 in QNAP Network Attached Storage (NAS) is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 31 March 2022
US federal deadline
21 April 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.78Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.09 on 31 March 2022EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.

CISA's description

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

The CVE record's description, from qnap

CVE published
13 May 2021
Assigned by
qnap
CVSS
10.0 Critical (CVSS 3.1, from the CNA)
CWE-285
Improper Authorization
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Network Attached Storage (NAS): other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2018-19949NAS File Station Command InjectionQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.28
CVE-2018-19953NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.29
CVE-2018-19943NAS File Station Cross-Site ScriptingQNAP Network Attached Storage (NAS)Patch this weekRansomware use0.21

Read further