Cyber & AI intelligence
Wasteland.
Briefs indexed2982
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2023-54405 2026-10-02

H3C CVM Unauthenticated File Upload Flaw Enables Remote Code Execution (CVE-2023-54405)

"CVE-2023-54405 is a critical (CVSS 9.8) unauthenticated arbitrary file upload vulnerability in H3C CVM that lets remote attackers plant a JSP web shell and run code. According to the NVD description, the Shadowserver…"

CVE-2023-54405 is a critical (CVSS 9.8) unauthenticated arbitrary file upload vulnerability in H3C CVM that lets remote attackers plant a JSP web shell and run code. According to the NVD description, the Shadowserver Foundation saw exploitation evidence as early as October 2023.

What Is It

H3C CVM is the Cloud Virtualization Management component of the H3C CAS cloud platform. Its /cas/fileUpload/upload endpoint has an arbitrary file upload flaw that requires no authentication. The endpoint does not check the caller-supplied token parameter for path traversal, and it does not restrict file types. An attacker can use path traversal in token to write a malicious JSP file into a web-accessible directory. Requesting that file then runs code as the web-server user.

The weakness is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). VulnCheck reported the flaw. NVD published it on 2026-10-02, and its status is currently "Received."

Why It Matters

A management-plane server that gets compromised in a virtualization environment is a high-value foothold. Treat exposed instances as urgent.

What's Vulnerable

Patch Status

The supplied NVD record does not identify a vendor patch, a fixed version, or an official workaround. The H3C reference is the CAS CVM user guide, not a security advisory. The record contains no remediation guidance and no CISA required action.

Owners of H3C CVM deployments should check with H3C for fixes. They should also review whether /cas/fileUpload/upload is reachable from untrusted networks. Because exploitation evidence dates back to 2023, they should look in web-accessible directories for JSP files they don't recognize.

Sources