CVE-2025-2775

9.5 CISA KEV

SysAid · SysAid On-Prem

SysAid On-Prem contains an unauthenticated XML External Entity (XXE) vulnerability in its Checkin processing, enabling unauthorized file reading and potential administrator account takeover.

Executive summary

SysAid On-Prem is currently subject to active exploitation in the wild, requiring immediate patching to prevent unauthenticated remote attackers from compromising administrative credentials.

Vulnerability

This vulnerability is an unauthenticated XML External Entity (XXE) injection flaw located within the Checkin processing functionality of the application. An unauthenticated attacker can exploit this to read arbitrary files from the host server or perform administrative account takeover, which may serve as a precursor to full remote command execution.

Business impact

The criticality of this vulnerability is underscored by its CVSS score of 9.5 and its inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. Successful exploitation allows an attacker to bypass authentication, access sensitive system files, and gain administrative control over the ITSM platform. Given that ITSM solutions typically house highly sensitive internal documentation, asset inventories, and incident data, this flaw poses an extreme risk of data exfiltration and total system compromise.

Remediation

Immediate Action: Update all SysAid On-Prem instances to version v24.4.60 or later immediately to remediate the vulnerability.

Proactive Monitoring: Review application logs for unusual XML-based requests, especially those directed at the /mdm/checkin endpoint, and monitor for unexpected administrative account activity.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block malicious XML payloads and filter requests containing external entity definitions.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented by watchTowr Labs.

Analyst recommendation

Due to confirmed active exploitation and the critical severity of this vulnerability, organizations must treat this as a top-priority remediation task. The ability for unauthenticated attackers to achieve administrative takeover necessitates an immediate upgrade to version v24.4.60 to close the attack vector and prevent further unauthorized access to your environment.

More SysAid CVEs

Sources

Originally found and disclosed by Sina Kheirkhah (@SinSinology), Jake Knott, with watchTowr (sponsor), per the CVE Program record.