CISA Known Exploited Vulnerability

CVE-2021-28799 Ransomware

QNAP · Network Attached Storage (NAS)

QNAP NAS Improper Authorization Vulnerability

Date added
BOD 22-01 due date
CWE CWE-285
Ransomware Known

CISA description

QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.

Required action

Apply updates per vendor instructions.