ZeroHour

CVE-2023-47246

KEV ransomware PoC moderate

Unauthenticated Path Traversal RCE in SysAid On-Premise Server

CISA: SysAid Server Path Traversal Vulnerability

CVSS 3.1
9.8 critical
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2023-47246 is a critical (CVSS 9.8) path traversal flaw (CWE-22) in SysAid On-Premise before version 23.3.36 that allows an unauthenticated, network-located attacker to write attacker-controlled files into the Tomcat webroot of the SysAid server. Once a file is written into that webroot, it is executed by the Tomcat application server, resulting in remote code execution on the ITSM server. Because the flaw requires no authentication or user interaction, any internet-exposed SysAid On-Premise server is directly reachable, and compromise can lead to data theft and ransomware deployment; the Lace Tempest group behind the MOVEit attacks has exploited it, and ransomware use is known. Only SysAid On-Premise deployments are affected, and the vendor fixed the issue in version 23.3.36. The vulnerability is confirmed exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-13, and carries a 98.9% EPSS probability of exploitation within 30 days.

What to do: Upgrade SysAid On-Premise to version 23.3.36 or later immediately, per the vendor's security notification. Because this is KEV-listed with known ransomware use by Lace Tempest, also inspect the Tomcat webroot and deployed webapps for unauthorized files (e.g., WAR files), review for unauthorized accounts and unusual processes, and check for signs of lateral movement on compromised hosts. Organizations unable to patch should apply mitigations per the vendor's instructions or discontinue use of the product, per the CISA required action.

Affected
SysAid On-Premise (SysAid Server)before 23.3.36
Estimated exposure
moderate≈ a few thousand internet-exposed SysAid On-Premise servers (SysAid's overall customer base is on the order of tens of thousands of organizations, and only the… — Estimate based on SysAid's on-premise deployment model of roughly one server per organization, public internet-exposure scan reporting around the November 2023 disclosure showing on the order of ~2,000 exposed instances, and the fact that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

CISA Known Exploited Vulnerability
Affected
SysAid SysAid Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
sysaid
Products
sysaid
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news