CISA KEV · catalog date Mar 31, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-28799
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
Exploited in the wild (CISA KEV since Mar 31, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 78.3% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
- State
- PUBLISHED
- Published
- May 13, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 90%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAqnapOriginal evidence ↗
Record text: Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
Inspect raw assertion
- Field
container- Value
- Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: QNAP NAS Improper Authorization Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- QNAP NAS Improper Authorization Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 78.25% probability · 99.54th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.782500000000; percentile 0.995430000000
FIRST EPSS · score date Aug 27, 2026 · 99.5th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
Inspect raw assertion
- Field
container- Value
- Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
QNAP NAS Improper Authorization Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- QNAP NAS Improper Authorization Vulnerability
78.25% probability · 99.54th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.782500000000; percentile 0.995430000000
Applicability
Cited product scope
Grouped from 10 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
12 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "all versions"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "unaffected", "version": "all versions"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "unspecified", "lessThan": "v3.0.210411", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "unspecified", "lessThan": "v3.0.210411", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "unspecified", "lessThan": "v16.0.0415", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "unspecified", "lessThan": "v16.0.0419", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "unspecified", "lessThan": "v16.0.0419", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "unspecified", "lessThan": "v3.0.210412", "versionType": "custom"}]product-aa0cb885c8e4a48ef6d9ad1bbf0eac10c521be0c4bb3395bc55ce2713d11cf25Linked exactInspect raw assertions
cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 16.0.0415
- Match ID
a18656f9-afb4-44bc-af08-e1a0a5d2ef49
cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 3.0.210411
- Match ID
78491b95-5835-411b-b188-30e496bcb10a
cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 16.0.0419
- Match ID
bb2a5649-4bb9-46e9-8a1a-b6046125bd92
cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 16.0.0419
- Match ID
bb2a5649-4bb9-46e9-8a1a-b6046125bd92
cpe:2.3:a:qnap:hybrid_backup_sync:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 3.0.210412
- Match ID
d5920ea4-eea5-4f64-b06b-eed06e824864
product-81578b5d517b13c57b34c6184dee501c7b2e69f5d366148b8e0d95265e548fc9Linked exactInspect raw assertions
cpe:2.3:o:qnap:qts:4.3.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f0c7d2d4-769f-4297-89f4-75366ffa7618
cpe:2.3:o:qnap:qts:4.3.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fe9fac96-aa2a-4ca5-a170-8c0e6bd47391
cpe:2.3:o:qnap:qts:4.5.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1ac8bd83-ea71-4af8-aaec-e46efca99ea2
cpe:2.3:o:qnap:qts:4.3.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c5994c07-17fe-4784-9fa4-9675ba8b4743
product-c10aad70cb83f936b6928d1401d2eb8acec8be0afd0b3faf9080032603a271eeLinked exactInspect raw assertion
cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- from including c4.5.1; through including c4.5.4
- Match ID
fedf704d-d5ad-45c2-ad7d-e53189c72e1a
product-0a6983be8c95a10c38b798686f8b7e66f22caa6fe0e778c8bc34c7c367ce8dafLinked exactInspect raw assertion
cpe:2.3:o:qnap:quts_hero:h4.5.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
548228b3-eb2c-42c1-895b-da6dc5ca26ee
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-37a503905b0a0167877af753ac60ba6a9fd40363b081ec9e83c43aeaec72163a · product-aa0cb885c8e4a48ef6d9ad1bbf0eac10c521be0c4bb3395bc55ce2713d11cf25
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1600a652-eb41-4831-9be7-d3549e0374bf2f3bb281-2146-45ef-aa76-0759689529015727c75a-e8d0-44dc-9584-a436fbdc690c8317134b-1b77-4b83-844a-64d794cc06f283cbddf5-a642-4f0b-9050-cb35c884aa05Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 8
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
126ad47b-5eb1-4494-857c-cb980e18b5a82b10ee80-5a5d-4733-b881-eda04b16bfae34248e1a-a7f5-4aed-8e78-78ab0a3b012274ca4f22-7bc2-42b0-97d4-f9cb563d214c9d21b1b9-9511-40c9-8625-181428bd0c079fd7f325-ef57-4748-ad17-aa6b9bdf4126a6c2d521-d67d-4849-ad89-7aabe0b93988d95248c6-67a4-433e-bdd4-4935c2b17348Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HDirect CVE/CNA normalized decisions
qnap
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 10.0
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.