EXPOSURES › CVE-2021-28799
CVE-2021-28799
CRITICAL ⌖ ON CISA KEV · EXPLOITEDQNAP NAS devices with HBS 3 allowed unauthorized remote logins due to an improper authorization vulnerability, actively exploited in ransomware attacks.
A vulnerability in QNAP NAS devices running HBS 3 enabled remote attackers to log in without proper authorization, leading to potential data breaches and ransomware infections. DIB organizations using these devices face significant compliance risks (NIST 800-171 controls 3.A.1, 3.B.1) and should immediately patch or isolate affected systems. Verify vendor security advisories and implement robust access controls.
Shame score — The vulnerability's exploitation in ransomware attacks and the ease of unauthorized access demonstrate a significant failure in access control implementation, highlighting negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.