CVE-2021-28799
KEV ransomwaremass1Improper Authorization in QNAP HBS 3 Allows Remote Login to NAS Devices
CISA: QNAP NAS Improper Authorization Vulnerability
CVE-2021-28799 is a critical improper authorization flaw (CWE-285, CVSS 9.8) in HBS 3 (Hybrid Backup Sync), the backup application bundled with QNAP NAS firmware. Because the weakness is reachable over the network with no privileges and no user interaction, a remote attacker who can reach an affected NAS can bypass authorization and log in to the device. An attacker gaining this unauthorized login obtains remote access to the NAS, which threat actors have leveraged in ransomware campaigns against QNAP devices. Anyone running HBS 3 on QTS 4.3.3, 4.3.4, 4.3.6 or 4.5.2, QuTS hero h4.5.1, or QuTScloud c4.5.1-c4.5.4 at versions below the listed fixes is affected, while HBS 2 and HBS 1.3 are not affected. The flaw is in the wild: it was added to CISA's KEV on 2022-03-31 with known ransomware use, EPSS puts 30-day exploitation probability at 78.3% (top percentile), and public reporting around this period describes ransomware waves (e.g., Qlocker, eCh0raix) infecting hundreds of QNAP NAS devices within days.
What to do: Update HBS 3 to the fix for your OS: v16.0.0415 on QTS 4.5.2, v3.0.210412 on QTS 4.3.6, v3.0.210411 on QTS 4.3.4/4.3.3, and v16.0.0419 on QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4. Until patched, keep the NAS and its web services off the direct internet (disable router port forwarding/UPnP to the NAS) and review devices for signs of compromise. Given the KEV listing and known ransomware use, prioritize internet-reachable NAS devices.
| QNAP Systems Inc. HBS 3 (Hybrid Backup Sync) on QTS | prior to v16.0.0415 on QTS 4.5.2; prior to v3.0.210412 on QTS 4.3.6; prior to v3.0.210411 on QTS 4.3.4; prior to v3.0.210411 on QTS 4.3.3 |
| QNAP Systems Inc. HBS 3 (Hybrid Backup Sync) on QuTS hero | prior to v16.0.0419 on QuTS hero h4.5.1 |
| QNAP Systems Inc. HBS 3 (Hybrid Backup Sync) on QuTScloud | prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4 |
| QNAP Systems Inc. QNAP Network Attached Storage (NAS) running HBS 3 | all HBS 3 versions in the ranges above on the listed QTS/QuTS/QuTScloud builds; HBS 2 and HBS 1.3 are not affected |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
- Affected
- QNAP Network Attached Storage (NAS)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- qnap
- Products
- hybrid backup sync
- Weakness
- CWE-285
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H