Vulnerability Intelligence Report
Missing Authentication for Critical Function in RTRR Server in HBS3
CVE-2021-28809
An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS 3: QTS 4.3.6: HBS 3 v3.0.210507 and later QTS 4.3.4: HBS 3 v3.0.210506 and later QTS 4.3.3: HBS 3 v3.0.210506 and later
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:15.80%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-284 ↗CWE-284 Improper Access Control
CWE-306 ↗CWE-306 Missing Authentication for Critical Function
CWE-749 ↗CWE-749 Exposed Dangerous Method or Function
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| QNAP Systems Inc. | HBS 3 | unspecified < v3.0.210507 (affected) |
| QNAP Systems Inc. | HBS 3 | unspecified < v3.0.210506 (affected) |
| QNAP Systems Inc. | HBS 3 | unspecified < v3.0.210506 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
15.802%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | QNAP Systems, Inc. · Vendor · Taiwan |
| Reserved | 2021-03-18T00:00:00 |
| Published | 2021-07-08T07:40:12 |
| Patch Date | 2021-07-08 |
| Last Updated | 2024-09-17T00:36:54 |
Community Chatter & Buzz