ZeroHour

CVE-2021-28799

KEV ransomwaremass1

Improper Authorization in QNAP HBS 3 Allows Remote Login to NAS Devices

CISA: QNAP NAS Improper Authorization Vulnerability

CVSS 3.1
9.8 critical
EPSS
78%p100
Published
()
KEV added
AI analysis

CVE-2021-28799 is a critical improper authorization flaw (CWE-285, CVSS 9.8) in HBS 3 (Hybrid Backup Sync), the backup application bundled with QNAP NAS firmware. Because the weakness is reachable over the network with no privileges and no user interaction, a remote attacker who can reach an affected NAS can bypass authorization and log in to the device. An attacker gaining this unauthorized login obtains remote access to the NAS, which threat actors have leveraged in ransomware campaigns against QNAP devices. Anyone running HBS 3 on QTS 4.3.3, 4.3.4, 4.3.6 or 4.5.2, QuTS hero h4.5.1, or QuTScloud c4.5.1-c4.5.4 at versions below the listed fixes is affected, while HBS 2 and HBS 1.3 are not affected. The flaw is in the wild: it was added to CISA's KEV on 2022-03-31 with known ransomware use, EPSS puts 30-day exploitation probability at 78.3% (top percentile), and public reporting around this period describes ransomware waves (e.g., Qlocker, eCh0raix) infecting hundreds of QNAP NAS devices within days.

What to do: Update HBS 3 to the fix for your OS: v16.0.0415 on QTS 4.5.2, v3.0.210412 on QTS 4.3.6, v3.0.210411 on QTS 4.3.4/4.3.3, and v16.0.0419 on QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4. Until patched, keep the NAS and its web services off the direct internet (disable router port forwarding/UPnP to the NAS) and review devices for signs of compromise. Given the KEV listing and known ransomware use, prioritize internet-reachable NAS devices.

Affected
QNAP Systems Inc. HBS 3 (Hybrid Backup Sync) on QTSprior to v16.0.0415 on QTS 4.5.2; prior to v3.0.210412 on QTS 4.3.6; prior to v3.0.210411 on QTS 4.3.4; prior to v3.0.210411 on QTS 4.3.3
QNAP Systems Inc. HBS 3 (Hybrid Backup Sync) on QuTS heroprior to v16.0.0419 on QuTS hero h4.5.1
QNAP Systems Inc. HBS 3 (Hybrid Backup Sync) on QuTScloudprior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4
QNAP Systems Inc. QNAP Network Attached Storage (NAS) running HBS 3all HBS 3 versions in the ranges above on the listed QTS/QuTS/QuTScloud builds; HBS 2 and HBS 1.3 are not affected
Estimated exposure
mass≈1M+ QNAP NAS devices plausibly run an affected HBS 3 build (the app ships bundled with the affected QTS/QuTS releases), with hundreds of thousands of QNAP NAS… — QNAP's consumer/SMB NAS install base is in the millions and HBS 3 is bundled with the affected QTS/QuTS firmware generations, while public internet-wide scans around the disclosure period showed on the order of hundreds of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

CISA Known Exploited Vulnerability
Affected
QNAP Network Attached Storage (NAS)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
qnap
Products
hybrid backup sync
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news