CVE-2023-54405 Overview
CVE-2023-54405 is an unauthenticated arbitrary file upload vulnerability in H3C Cloud Virtualization Management (CVM), the virtualization component of the H3C Cloud Automation System (CAS) platform. The flaw resides in the /cas/fileUpload/upload endpoint, which accepts a caller-supplied token parameter without validating path traversal sequences or restricting uploaded file types. Remote attackers can write arbitrary files, including JavaServer Pages (JSP) webshells, into web-accessible directories. Requesting the uploaded JSP yields remote code execution as the web-server user. The Shadowserver Foundation first observed exploitation evidence on 2023-10-14, and a public Nuclei detection template is available.
Critical Impact
Unauthenticated remote attackers can achieve full remote code execution on H3C CAS CVM servers by uploading JSP webshells through a path-traversal flaw in the token parameter.
Affected Products
- H3C Cloud Automation System (CAS) platform
- H3C Cloud Virtualization Management (CVM) component
- Deployments exposing the /cas/fileUpload/upload endpoint
Discovery Timeline
- 2023-10-14 - Exploitation evidence first observed by the Shadowserver Foundation
- 2026-10-02 - CVE-2023-54405 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2023-54405
Vulnerability Analysis
The vulnerability is classified as Unrestricted Upload of File with Dangerous Type [CWE-434]. The /cas/fileUpload/upload endpoint in H3C CVM accepts file uploads from unauthenticated callers and uses the client-supplied token parameter as part of the destination path. The handler does not sanitize the parameter for .. traversal sequences and does not enforce an allowlist of file extensions. An attacker can therefore direct writes outside the intended upload directory and place executable content, such as a JSP webshell, into any directory writable by the web-server process. According to VulnCheck's advisory, successful exploitation results in command execution with the privileges of the CAS web application.
Root Cause
Two input-validation failures combine to produce the flaw. First, the upload handler trusts the token parameter and incorporates it into the server-side file path without canonicalization. Second, the handler does not restrict the uploaded content type or extension, so server-executable files such as .jsp are permitted. The absence of an authentication requirement on /cas/fileUpload/upload removes the final control that would otherwise limit abuse to authorized operators.
Attack Vector
Exploitation is remote, network-based, and requires no credentials or user interaction. The attacker sends an HTTP POST request to /cas/fileUpload/upload with a crafted token parameter containing path-traversal sequences and a JSP payload in the multipart body. Once the file is written into a web-accessible directory under the CAS web root, the attacker issues a follow-up HTTP request to the uploaded JSP to execute operating-system commands as the web-server user. Public detection content, including the projectdiscovery Nuclei template, demonstrates the request pattern used to validate the issue.
Detection Methods for CVE-2023-54405
Indicators of Compromise
- Unauthenticated HTTP POST requests to /cas/fileUpload/upload containing .. or URL-encoded traversal sequences in the token parameter.
- Newly written .jsp, .jspx, or .war files under the CAS web root or any directory served by the Tomcat/CAS application.
- Subsequent GET requests to previously nonexistent JSP paths followed by shell command strings in query parameters.
- Child processes such as sh, bash, cmd.exe, whoami, or curl spawned by the CAS Java web-server process.
Detection Strategies
- Deploy the public Nuclei template for H3C CVM arbitrary file upload against internal CAS inventory to identify unpatched instances.
- Create web-server access-log rules that alert on POST requests to /cas/fileUpload/upload where the token parameter contains .., %2e%2e, or absolute path markers.
- Monitor file-integrity on CAS web directories for creation of server-executable files outside of change windows.
Monitoring Recommendations
- Forward CAS web-server access and application logs to a centralized analytics platform and retain them for post-incident review.
- Alert on any process execution descending from the CAS Java process, which should not normally spawn shells or network utilities.
- Track egress connections from CAS servers to unexpected destinations, which may indicate webshell callbacks or secondary tooling downloads.
How to Mitigate CVE-2023-54405
Immediate Actions Required
- Restrict network access to the CAS management interface so that only trusted administrative networks can reach /cas/fileUpload/upload.
- Inspect CAS web directories for unauthorized .jsp, .jspx, or .war files and remove any that cannot be attributed to legitimate deployment activity.
- Review web-server access logs for prior requests to the vulnerable endpoint and treat matches as potential compromise.
- Rotate credentials, API tokens, and keys stored on or accessible from affected CAS hosts.
Patch Information
At time of publication, no fixed version is listed in the NVD entry for CVE-2023-54405. Administrators should consult the H3C CAS CVM product documentation and the VulnCheck advisory for the latest vendor guidance and apply any released hotfixes immediately.
Workarounds
- Block external access to /cas/fileUpload/upload at a reverse proxy or web application firewall and permit only authenticated administrative sources.
- Add WAF rules that reject requests to the endpoint when the token parameter contains path-traversal sequences or when the uploaded filename ends in a server-executable extension.
- Configure the application server so that upload destination directories are mounted non-executable, preventing JSP interpretation of attacker-written files.
- Place CAS management interfaces behind a VPN or jump host rather than exposing them directly to the internet.
# Example NGINX reverse-proxy rule to block traversal in the token parameter
location /cas/fileUpload/upload {
if ($arg_token ~* "(\.\./|%2e%2e|/etc/|\.jsp)") {
return 403;
}
proxy_pass http://cas_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.