CRITICAL 9.3 NVD

CVE-2023-54405

H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /ca

H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token parameter to upload a malicious JSP file into a web-accessible directory and then request it to achieve remote code execution as the web-server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.

References

Published: 2026-10-02 · Source: NVD · Feed updated: 2026-10-02
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-10-02 via NVD.

Risk Timeline

CVE Disclosed2026-10-02 · -1 days ago

Remediation Resources

vulnfeed aggregates 10027 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.