Unauthenticated Arbitrary File Upload in H3C CVM Third-Party Cloud Solution
CVE-2023-54405

9.3CRITICAL

Key Information:

Vendor

H3c

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2023-54405?

The Cloud Virtualization Management (CVM) component of the H3C CAS cloud platform is susceptible to an unauthenticated file upload vulnerability. The flaw exists due to insufficient validation of the 'token' parameter in the /cas/fileUpload/upload endpoint. Attackers can exploit this vulnerability by manipulating the token parameter to upload unauthorized files, including potentially harmful .JSP files, to a directory accessible via the web. This exploitation allows attackers to execute arbitrary code on the server, potentially compromising the web server's integrity and security.

Affected Version(s)

CVM *

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Shadowserver Foundation
.