Unauthenticated Arbitrary File Upload in H3C CAS CVM
H3C CAS CVM contains an unauthenticated arbitrary file upload vulnerability via path traversal, allowing remote attackers to achieve remote code execution by uploading malicious JSP files.
CVE search metadata
CVE search record: CVE-2023-54405. Severity: critical. CVSS: 9.8. KEV: no. Product: CAS (CVM). Brief: Unauthenticated Arbitrary File Upload in H3C CAS CVM. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2023-54405/
H3C CVM (Cloud Virtualization Management), a core component of the H3C CAS cloud platform, contains a critical unauthenticated arbitrary file upload vulnerability. The flaw exists within the /cas/fileUpload/upload endpoint, where the application fails to properly sanitize the 'token' parameter. An attacker can leverage path traversal sequences within this parameter to bypass intended file directory restrictions and write arbitrary files to the underlying web server.
By uploading a malicious JSP file to a web-accessible directory, an unauthenticated attacker can subsequently execute arbitrary commands by requesting the uploaded file, resulting in code execution with the privileges of the web server user. This vulnerability was first observed being exploited in the wild on October 14, 2023, as documented by the Shadowserver Foundation. Organizations utilizing H3C CAS should immediately audit their web server access logs for anomalous requests to the file upload endpoint and implement necessary vendor patches or mitigations to prevent unauthenticated access.
Attack Chain
- Attacker identifies an internet-facing H3C CAS instance running vulnerable CVM components.
- Attacker crafts a malicious HTTP POST request targeting the /cas/fileUpload/upload endpoint.
- Attacker injects path traversal payloads (e.g., ../../) into the 'token' parameter to manipulate the destination directory.
- Application fails to validate the path, allowing the attacker to specify an arbitrary destination on the file system.
- Attacker uploads a JSP web shell, placing it within a directory accessible by the web server's document root.
- Attacker sends a GET request to the path of the newly uploaded JSP file.
- The web server executes the malicious JSP code upon request.
- Attacker gains remote code execution on the target host as the web server user.
Impact
Successful exploitation allows for full remote code execution on H3C CAS CVM instances. This permits attackers to gain complete control over the affected virtualization management server, potentially leading to unauthorized data exfiltration, lateral movement within the data center, and the compromise of hosted virtualized environments. Given the nature of CAS as a virtualization management platform, the impact to confidentiality, integrity, and availability of the entire cloud infrastructure is severe.
Recommendation
Prioritize the identification and patching of all internet-exposed H3C CAS installations. Monitor web access logs for suspicious HTTP POST requests directed at the /cas/fileUpload/upload URI, specifically inspecting the 'token' parameter for path traversal patterns (e.g., "../"). Deploy the provided Sigma rule to detect exploitation attempts and tune based on legitimate administrative file upload patterns.
- Search web server logs for HTTP POST requests to /cas/fileUpload/upload containing path traversal sequences in the 'token' query parameter.
- Apply security updates for H3C CAS as provided by the vendor to remediate CVE-2023-54405.
- Implement access control restrictions at the network layer to limit access to the H3C CAS management interface to trusted internal segments only.
Immediate actions
Deploy Sigma detection rule for CVE-2023-54405
Mitigations
Patch H3C CAS instance to the version remediating CVE-2023-54405
CVE-2023-54405
Detection coverage 1
Detect CVE-2023-54405 Exploitation - Path Traversal in H3C CVM Upload
criticalDetects exploitation attempts against H3C CVM where path traversal sequences are used in the token parameter to upload files to arbitrary locations.
Detection queries are available on the platform. Get full rules →