CVE-2023-54405 is an unauthenticated arbitrary file upload vulnerability in H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform. The file-upload endpoint accepts a caller-supplied token parameter without restricting path traversal or uploaded file types. Remote attackers can manipulate this parameter to write arbitrary files, including malicious JSP files in web-accessible directories, and then request those files to execute code as the web-server user. The Shadowserver Foundation first observed exploitation evidence on October 14, 2023. Specific affected versions are not identified.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated arbitrary file upload vulnerability in H3C CVM, the Cloud Virtualization Management component of H3C CAS. Manipulating the caller-supplied token parameter permits path traversal without file-type restrictions. Remote attackers can upload a malicious JSP file into a web-accessible directory and request it to execute code as the web-server user.
An unauthenticated arbitrary file upload vulnerability in H3C CVM allows remote attackers to manipulate the caller-supplied token parameter using path traversal and upload arbitrary files without file-type restrictions. Uploading a malicious JSP file into a web-accessible directory and requesting it enables remote code execution as the web-server user. The supplied CVSS vectors indicate network exploitation with low complexity, no privileges or user interaction, and high confidentiality, integrity, and availability impact.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.