{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ah3ccas/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:h3c:cas:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-54405"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CAS (CVM)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","cloud-security","cve-2023-54405"],"_cs_type":"threat","_cs_vendors":["H3C"],"content_html":"\u003cp\u003eH3C CVM (Cloud Virtualization Management), a core component of the H3C CAS cloud platform, contains a critical unauthenticated arbitrary file upload vulnerability. The flaw exists within the /cas/fileUpload/upload endpoint, where the application fails to properly sanitize the 'token' parameter. An attacker can leverage path traversal sequences within this parameter to bypass intended file directory restrictions and write arbitrary files to the underlying web server.\u003c/p\u003e\n\u003cp\u003eBy uploading a malicious JSP file to a web-accessible directory, an unauthenticated attacker can subsequently execute arbitrary commands by requesting the uploaded file, resulting in code execution with the privileges of the web server user. This vulnerability was first observed being exploited in the wild on October 14, 2023, as documented by the Shadowserver Foundation. Organizations utilizing H3C CAS should immediately audit their web server access logs for anomalous requests to the file upload endpoint and implement necessary vendor patches or mitigations to prevent unauthenticated access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing H3C CAS instance running vulnerable CVM components.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request targeting the /cas/fileUpload/upload endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects path traversal payloads (e.g., ../../) into the 'token' parameter to manipulate the destination directory.\u003c/li\u003e\n\u003cli\u003eApplication fails to validate the path, allowing the attacker to specify an arbitrary destination on the file system.\u003c/li\u003e\n\u003cli\u003eAttacker uploads a JSP web shell, placing it within a directory accessible by the web server's document root.\u003c/li\u003e\n\u003cli\u003eAttacker sends a GET request to the path of the newly uploaded JSP file.\u003c/li\u003e\n\u003cli\u003eThe web server executes the malicious JSP code upon request.\u003c/li\u003e\n\u003cli\u003eAttacker gains remote code execution on the target host as the web server user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full remote code execution on H3C CAS CVM instances. This permits attackers to gain complete control over the affected virtualization management server, potentially leading to unauthorized data exfiltration, lateral movement within the data center, and the compromise of hosted virtualized environments. Given the nature of CAS as a virtualization management platform, the impact to confidentiality, integrity, and availability of the entire cloud infrastructure is severe.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all internet-exposed H3C CAS installations. Monitor web access logs for suspicious HTTP POST requests directed at the /cas/fileUpload/upload URI, specifically inspecting the 'token' parameter for path traversal patterns (e.g., \u0026quot;../\u0026quot;). Deploy the provided Sigma rule to detect exploitation attempts and tune based on legitimate administrative file upload patterns.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSearch web server logs for HTTP POST requests to /cas/fileUpload/upload containing path traversal sequences in the 'token' query parameter.\u003c/li\u003e\n\u003cli\u003eApply security updates for H3C CAS as provided by the vendor to remediate CVE-2023-54405.\u003c/li\u003e\n\u003cli\u003eImplement access control restrictions at the network layer to limit access to the H3C CAS management interface to trusted internal segments only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T20:26:29Z","date_published":"2026-10-02T20:26:29Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2023-54405/","summary":"H3C CAS CVM contains an unauthenticated arbitrary file upload vulnerability via path traversal, allowing remote attackers to achieve remote code execution by uploading malicious JSP files.","title":"Unauthenticated Arbitrary File Upload in H3C CAS CVM","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2023-54405/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:h3c:cas:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}