QNAP Systems HBS 3是中国威联通科技(QNAP Systems)公司的一个应用系统。一种全面的数据备份和灾难恢复解决方案。 QNAP Systems HBS 3 Hybrid Backup Sync 存在安全漏洞,该漏洞源于没有充分的授权检查。攻击者可利用该漏洞可以绕过授权检查,直接登录设备。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| QNAP Systems Inc. | HBS 3 | unspecified ~ v16.0.0415 | - |
|
| QNAP Systems Inc. | HBS 3 | unspecified ~ v3.0.210412 | - |
|
| QNAP Systems Inc. | HBS 3 | unspecified ~ v3.0.210411 | - |
|
| QNAP Systems Inc. | HBS 3 | unspecified ~ v3.0.210411 | - |
|
| QNAP Systems Inc. | HBS 3 | unspecified ~ v16.0.0419 | - |
|
| QNAP Systems Inc. | HBS 3 | unspecified ~ v16.0.0419 | - |
|
| QNAP Systems Inc. | HBS 2 | all versions | - |
|
| QNAP Systems Inc. | HBS 1.3 | all versions | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 . | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-28799.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-36197 | 7.1 HIGH | Improper Access Control Vulnerability in Music Station |
| CVE-2020-36198 | 6.7 MEDIUM | Command Injection Vulnerability in Malware Remover |
No comments yet