CVE-2025-2775
CRITICAL(9.3)KEVElevated Risk
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:LOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| sysaid | sysaid | <= 23.3.40 |
Multiple CVSS Assessments
Source: [email protected](Secondary)
9.3
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Source: [email protected](Primary)
7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References
- https://documentation.sysaid.com/docs/24-40-60(Release Notes)
- https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/(Exploit, Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-2775(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.