CVE-2021-28799
QNAP NAS Improper Authorization Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9.8
- EPSS
- 78.4% 백분위 99.5% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.04.21
- 공개일
- 2021.05.13
CISA KEV에 등록된 실제 악용 확인 취약점
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
공급사 QNAP
제품 Network Attached Storage (NAS)
영향 버전 unspecified, < 16.0.0415, < 3.0.210412, < 3.0.210411, < 16.0.0419
수정 버전 16.0.0415, 3.0.210412, 3.0.210411, 16.0.0419
Apply updates per vendor instructions.
조치 기한: 2022.04.21CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-285
KEV 등록일 2022.03.31
랜섬웨어 캠페인 사용 확인됨
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2021-28799
EPSS 데이터 기준일 2026.06.27