---
id: CVE-2024-13980
title: >-
  H3C Intelligent Management Center (IMC) versions up to and including E0632H07
  contains a remote command execution vulnerability in the /byod/index.xhtml
  endpoint
summary: >-
  H3C Intelligent Management Center (IMC) versions up to and including E0632H07
  contains a remote command execution vulnerability in the /byod/index.xhtml
  endpoint. Improper handling of JSF ViewState allows unauthenticated attackers
  to cra…
severity: none
cwe:
  - CWE-502
published: '2025-08-27'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-13980'
references:
  - url: 'https://axsec.blog.csdn.net/article/details/141003376'
    label: disclosure@vulncheck.com
  - url: 'https://blog.csdn.net/nnn2188185/article/details/141065540'
    label: disclosure@vulncheck.com
  - url: 'https://blog.csdn.net/weixin_48539059/article/details/141033966'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/OJZen/FckESC/blob/master/%E5%86%85%E7%BD%91%E7%99%BB%E5%BD%95%E8%BF%87%E7%A8%8B.txt
    label: disclosure@vulncheck.com
  - url: 'https://www.h3c.com/cn/Service/Online_Help/psirt/'
    label: disclosure@vulncheck.com
  - url: 'https://www.vulncheck.com/advisories/h3c-intelligent-management-center-rce'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00961
epssPercentile: 0.60072
ingestedAt: '2026-09-26T21:38:01.480Z'
---

## Overview

H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint. Improper handling of JSF ViewState allows unauthenticated attackers to craft POST requests with forged javax.faces.ViewState parameters, potentially leading to arbitrary command execution. This flaw does not require authentication and may be exploited without session cookies. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-08-28 UTC.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
