CVE-2025-2777
PoC largeUnauthenticated XXE in SysAid On-Prem <= 23.3.40 Enables Admin Takeover
SysAid On-Prem versions 23.3.40 and earlier contain an unauthenticated XML External Entity (XXE) injection flaw (CWE-611) in the functionality that processes lshw (hardware inventory) data. Because the XML parser resolves external entities from network-supplied input without requiring authentication, a remote attacker can inject malicious entity definitions into lshw processing requests. Successful exploitation yields arbitrary file-read primitives and can be leveraged to take over an administrator account (CVSS 3.1: 9.8). All organizations running affected on-premises SysAid builds are in scope; cloud-hosted SysAid is not named in the advisory. Exploitation is likely in the wild: CISA has warned that SysAid flaws enabling remote file access and SSRF are under active attack, a public PoC has been released, and EPSS puts the 30-day exploitation probability at 72.2%.
What to do: Upgrade SysAid On-Prem to a patched release newer than 23.3.40 as soon as possible (the vendor has patched this and related pre-auth flaws, per recent headlines). Until patched, minimize the server's internet exposure and restrict its outbound network access, since XXE exploitation can depend on the server resolving attacker-controlled external entities. Review logs for unexpected unauthenticated lshw/XML requests and for signs of administrator account changes or unusual file access.
| SysAid On-Prem | <= 23.3.40 (all on-premises builds up to and including 23.3.40) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.
- Vendors
- sysaid
- Products
- sysaid
- Weakness
- CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H