← Back

CVE-2021-28809

nvd nist
Published: Jul 8, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later

Affected (2)

1 product
Hybrid Backup Sync
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.0.210507
Running on/withPlatform Versions
Qnap
Qts
Version 4.3.6
Configuration B
1 platform
Running on/withPlatform Versions
Qnap
Qts
Version 4.3.4
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.0.210506
Running on/withPlatform Versions
Qnap
Qts
Version 4.3.3

References (4)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: security@qnapsecurity.com.tw
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.