Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-54405— H3C CVM Unauthenticated File Upload via fileUpload/upload Token

Quick assessment

Affected
H3C CVM
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

H3C CVM 是 H3C CAS 云计算平台中的云虚拟化管理组件,其 端点存在一个未授权任意文件上传漏洞。该漏洞允许远程攻击者通过操控用户提供的 token 参数,在不限制路径遍历和文件类型检查的情况下,写入任意文件。攻击者可利用 token 参数中的路径遍历缺陷,将恶意的 JSP 文件上传至可通过 Web 访问的目录,随后通过请求该文件,以 Web 服务器用户的身份实现远程代码执行。该漏洞的利用迹象最初于 2023 年 10 月 14 日被 Shadowserver 基金会发现。

CVSS 9.8 · Critical EPSS 0.59% · P46

Affected Version Matrix 1

VendorProduct Version RangeStatus
H3C CVM * affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-54405

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
H3C CVM Unauthenticated File Upload via fileUpload/upload Token
Source: CVE Program / CVE List V5
Vulnerability Description
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token parameter to upload a malicious JSP file into a web-accessible directory and then request it to achieve remote code execution as the web-server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
H3C CVM * -

II. Public POCs for CVE-2023-54405

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-54405

请登录查看更多情报信息。

Vendor Advisories for CVE-2023-54405 (1)

Proof of Concept for CVE-2023-54405 (1)

Security Blog Posts for CVE-2023-54405 (1)

Vendor Pages for CVE-2023-54405 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-54405

No comments yet


Leave a comment