ZeroHour

CVE-2025-2777

PoC large

Unauthenticated XXE in SysAid On-Prem <= 23.3.40 Enables Admin Takeover

CVSS 3.1
9.8 critical
EPSS
72%p99
Published
()
Modified
AI analysis

SysAid On-Prem versions 23.3.40 and earlier contain an unauthenticated XML External Entity (XXE) injection flaw (CWE-611) in the functionality that processes lshw (hardware inventory) data. Because the XML parser resolves external entities from network-supplied input without requiring authentication, a remote attacker can inject malicious entity definitions into lshw processing requests. Successful exploitation yields arbitrary file-read primitives and can be leveraged to take over an administrator account (CVSS 3.1: 9.8). All organizations running affected on-premises SysAid builds are in scope; cloud-hosted SysAid is not named in the advisory. Exploitation is likely in the wild: CISA has warned that SysAid flaws enabling remote file access and SSRF are under active attack, a public PoC has been released, and EPSS puts the 30-day exploitation probability at 72.2%.

What to do: Upgrade SysAid On-Prem to a patched release newer than 23.3.40 as soon as possible (the vendor has patched this and related pre-auth flaws, per recent headlines). Until patched, minimize the server's internet exposure and restrict its outbound network access, since XXE exploitation can depend on the server resolving attacker-controlled external entities. Review logs for unexpected unauthenticated lshw/XML requests and for signs of administrator account changes or unusual file access.

Affected
SysAid On-Prem<= 23.3.40 (all on-premises builds up to and including 23.3.40)
Estimated exposure
largetens of thousands of on-prem deployments, with thousands of instances internet-exposed in public scans — SysAid is a widely deployed ITSM/helpdesk platform marketed to tens of thousands of organizations, and public internet scans of on-prem SysAid servers consistently surface thousands of exposed instances, so the population of unpatched…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.

Vendors
sysaid
Products
sysaid
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news