CVE-2023-54405: H3C CVM Unauthenticated File Upload via fileUpload/upload Token
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token parameter to upload a malicious JSP file into a web-accessible directory and then request it to achieve remote code execution as the web-server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Any internet-reachable H3C CVM instance with the /cas/fileUpload/upload endpoint accessible is exposed. The vulnerability requires no authentication or user interaction.
What does an attacker need to do to gain code execution?
An attacker can manipulate the caller-supplied token parameter to traverse directories and upload a malicious JSP file into a web-accessible location. Requesting that uploaded JSP can result in remote code execution as the web-server user.
How can defenders identify possible compromise?
Review requests to /cas/fileUpload/upload, especially token values containing path-traversal sequences, and inspect web-accessible directories for unexpected JSP files. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.