CVE-2023-54405 is a critical (CVSS 9.8) unauthenticated arbitrary file upload vulnerability in H3C CVM that lets remote attackers plant a JSP web shell and run code. According to the NVD description, the Shadowserver Foundation saw exploitation evidence as early as October 2023.
What Is It
H3C CVM is the Cloud Virtualization Management component of the H3C CAS cloud platform. Its /cas/fileUpload/upload endpoint has an arbitrary file upload flaw that requires no authentication. The endpoint does not check the caller-supplied token parameter for path traversal, and it does not restrict file types. An attacker can use path traversal in token to write a malicious JSP file into a web-accessible directory. Requesting that file then runs code as the web-server user.
The weakness is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). VulnCheck reported the flaw. NVD published it on 2026-10-02, and its status is currently "Received."
Why It Matters
- Severity: CVSS 3.1 base score 9.8 (CRITICAL), vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. CVSS 4.0 base score 9.3 (CRITICAL). - No barriers: The attack works over the network, needs low complexity, and requires no privileges or user interaction.
- Exploited before disclosure: According to the NVD description, the Shadowserver Foundation first saw exploitation evidence on 2023-10-14. That is about three years before this CVE was published.
- Public tooling: The references include a ProjectDiscovery Nuclei template for this flaw, so scanning for it at scale is easy.
- KEV status: The supplied data has no CISA KEV entry for this CVE. KEV does not currently confirm active exploitation, and no CISA required action or due date exists.
A management-plane server that gets compromised in a virtualization environment is a high-value foothold. Treat exposed instances as urgent.
What's Vulnerable
- Vendor: H3C
- Product: CVM (H3C CAS Cloud Virtualization Management)
- Versions: All versions (
*) are listed as affected. No version ranges or CPEs are provided.
Patch Status
The supplied NVD record does not identify a vendor patch, a fixed version, or an official workaround. The H3C reference is the CAS CVM user guide, not a security advisory. The record contains no remediation guidance and no CISA required action.
Owners of H3C CVM deployments should check with H3C for fixes. They should also review whether /cas/fileUpload/upload is reachable from untrusted networks. Because exploitation evidence dates back to 2023, they should look in web-accessible directories for JSP files they don't recognize.