RULE(RULE ID:338554)

Rule General Information
Release Date: 2024-11-19
Rule Name: H3C-CVM fd Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: H3C CVM is a virtualization management system that realizes the central management and control of the virtualized environment of the data center. It uses a concise management interface to uniformly manage all physical and virtual resources in the data center. It not only improves administrators 'management and control capabilities and simplifies daily routines. Work can also reduce the complexity and management costs of the IT environment. The system/cas/fileUpload/fd interface has arbitrary file upload vulnerability. Unauthorized attackers can upload arbitrary files, obtain webshell, control server permissions, read sensitive information, etc.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.