Skip to content
COOEY

EXPOSURES › CVE-2021-28799

CVE-2021-28799

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-31 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-28799 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

QNAP NAS devices with HBS 3 allowed unauthorized remote logins due to an improper authorization vulnerability, actively exploited in ransomware attacks.

A vulnerability in QNAP NAS devices running HBS 3 enabled remote attackers to log in without proper authorization, leading to potential data breaches and ransomware infections. DIB organizations using these devices face significant compliance risks (NIST 800-171 controls 3.A.1, 3.B.1) and should immediately patch or isolate affected systems. Verify vendor security advisories and implement robust access controls.

Shame score — The vulnerability's exploitation in ransomware attacks and the ease of unauthorized access demonstrate a significant failure in access control implementation, highlighting negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.