
CVE-2023-54405 hits H3C's CVM, CVSS 9.8. An unauthenticated attacker manipulates the token parameter on its upload endpoint to traverse directories and plant a malicious JSP file, then requests it for remote code execution as the web server, no login needed. VulnTracker recommends upgrading CVM to the latest build now, exploitation evidence dates back to 2023. Details: http://vulntracker.io/cves/CVE-2023-54405 #H3C #CVM #CVE #InfoSec

