CVE-2025-2775
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 12 August 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 42.95% probability · 99th percentile
- CISA KEV
- Listed 22 July 2025 · due 12 August 2025
- Weakness
- CWE-611
- Affected
- sysaid/sysaid
- Source
- disclosure@vulncheck.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://documentation.sysaid.com/docs/24-40-60 ; https://nvd.nist.gov/vuln/detail/CVE-2025-2775
References
- https://documentation.sysaid.com/docs/24-40-60Release Notes
- https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/Exploit, Third Party Advisory
- https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-2775US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.