CVE-2021-28809
Estado: ModificadaCrítica (9.8)—
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 16%
- Percentil entre todas las CVEs puntuadas: 97
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-284, CWE-306, CWE-749
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-28809",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@qnapsecurity.com.tw",
"affectedData": [
{
"vendor": "QNAP Systems Inc.",
"product": "HBS 3",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "v3.0.210507",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.3.6"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "HBS 3",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "v3.0.210506",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.3.4"
]
},
{
"vendor": "QNAP Systems Inc.",
"product": "HBS 3",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "v3.0.210506",
"versionType": "custom"
}
],
"platforms": [
"QTS 4.3.3"
]
}
]
}
],
"published": "2021-07-08T08:15:07.663",
"references": [
{
"url": "https://www.qnap.com/en/security-advisory/qsa-21-19",
"tags": [
"Vendor Advisory"
],
"source": "security@qnapsecurity.com.tw"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-21-783/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "security@qnapsecurity.com.tw"
},
{
"url": "https://www.qnap.com/en/security-advisory/qsa-21-19",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-21-783/",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@qnapsecurity.com.tw",
"description": [
{
"lang": "en",
"value": "CWE-284"
},
{
"lang": "en",
"value": "CWE-306"
},
{
"lang": "en",
"value": "CWE-749"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later"
},
{
"lang": "es",
"value": "Se ha informado una vulnerabilidad de control de acceso inapropiado que afecta a determinadas versiones heredadas de HBS 3. Si es explotada, esta vulnerabilidad permite a atacantes comprometer la seguridad del sistema operativo.QNAP ya ha corregido esta vulnerabilidad en las siguientes versiones de HBS 3: QTS versiones 4.3.6: HBS 3 versiones v3.0.210507 y posteriores QTS versiones 4.3.4: HBS 3 versiones v3.0.210506 y posteriores"
}
],
"lastModified": "2026-06-17T03:46:54.160",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73C3E8C3-5764-47DB-B856-81F9FA4102C9",
"versionEndExcluding": "3.0.210507"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:4.3.6:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A0E214BD-DC96-4B53-9BE7-8DD8F79B4542"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A69482D0-EC1B-48D9-9A5F-99376D199D59",
"versionEndExcluding": "3.0.210506"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:4.3.4:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6A16F458-2E81-47E1-ADC8-5A93DF6FFC41"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A69482D0-EC1B-48D9-9A5F-99376D199D59",
"versionEndExcluding": "3.0.210506"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:4.3.3:-:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B16E7153-5F0F-489A-AA34-4A74CB04225B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security@qnapsecurity.com.tw"
}