CVE-2023-54405
Received Received - Intake

Unauthenticated Arbitrary File Upload in H3C CVM

Vulnerability report for CVE-2023-54405, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token parameter to upload a malicious JSP file into a web-accessible directory and then request it to achieve remote code execution as the web-server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
h3c cvm *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated arbitrary file upload flaw in H3C CVM, a cloud virtualization management component. Attackers can exploit the /cas/fileUpload/upload endpoint by manipulating the token parameter to upload malicious files, such as JSP web shells, without proper path traversal or file type restrictions. This allows remote code execution as the web server user by requesting the uploaded file.

Detection Guidance

To detect this vulnerability, you can send a POST request to the /cas/fileUpload/upload endpoint with a crafted token parameter containing a path traversal sequence and a test file. If the server responds with a 200 status code and the file is accessible via a GET request, the system is likely vulnerable. Example using curl: curl -X POST -F 'token=../../../test.jsp' -F 'file=@test.jsp' http://target/cas/fileUpload/upload. Then check if the file is accessible at http://target/test.jsp.

  • Use Nuclei with the H3C CVM arbitrary file upload template: nuclei -u http://target -t http/vulnerabilities/other/h3c-cvm-arbitrary-file-upload.yaml
Impact Analysis

This vulnerability can lead to unauthorized access to the system, manipulation of server permissions, exposure of sensitive data, and potential remote code execution. Attackers could gain control over the affected server, install malware, or steal confidential information.

Compliance Impact

This vulnerability allows remote attackers to upload arbitrary files, including malicious JSP files, to web-accessible directories. This could lead to unauthorized access, data exfiltration, or server compromise, which may violate compliance requirements for data protection and access control in standards like GDPR and HIPAA.

Mitigation Strategies

Immediately restrict access to the /cas/fileUpload/upload endpoint by blocking external requests or disabling the endpoint if not in use. Update H3C CVM to the latest patched version as soon as available. Monitor network traffic for suspicious POST requests to the vulnerable endpoint and inspect for unauthorized file uploads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-54405. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart