CVE-2024-13980 – H3C Intelligent Management Center Remote Command Execution Vulnerability

The following table lists the changes that have been made to the
CVE-2024-13980 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 27, 2025

    Action Type Old Value New Value
    Added Description H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint. Improper handling of JSF ViewState allows unauthenticated attackers to craft POST requests with forged javax.faces.ViewState parameters, potentially leading to arbitrary command execution. This flaw does not require authentication and may be exploited without session cookies. An affected version range is undefined.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-502
    Added Reference https://axsec.blog.csdn.net/article/details/141003376
    Added Reference https://blog.csdn.net/nnn2188185/article/details/141065540
    Added Reference https://blog.csdn.net/weixin_48539059/article/details/141033966
    Added Reference https://github.com/OJZen/FckESC/blob/master/%E5%86%85%E7%BD%91%E7%99%BB%E5%BD%95%E8%BF%87%E7%A8%8B.txt
    Added Reference https://www.h3c.com/cn/Service/Online_Help/psirt/
    Added Reference https://www.vulncheck.com/advisories/h3c-intelligent-management-center-rce
Share the Post:

Related Posts