← Back to browse · API

CVE-2021-28809

Severity
CRITICAL
CVSS
9.8
EPSS
0.15802
Risk score
44.73
CISA KEV
No
PoC
No
Published
2021-07-08
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2021-15465, GHSA-FWR8-WFF7-FMXW
Products
QNAP Systems Inc.:HBS 3 unspecified <v3.0.210506, QNAP Systems Inc.:HBS 3 unspecified <v3.0.210507
Sources
euvd EUVD-2021-15465

Description

An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later

References