CVE-2025-2777 is a critical unauthenticated XML External Entity (XXE) vulnerability affecting SysAid On-Prem versions up to 23.3.40, specifically within its lshw processing functionality. This flaw allows attackers to achieve administrator account takeover and read arbitrary files on the system. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog, exploit intelligence indicates the availability of Nuclei templates and public Proof-of-Concept (PoC) code, along with significant community discussion and media coverage, suggesting a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 23.3.40CPE matchmatch criteria | cpe:2.3:a:sysaid:sysaid:*:*:*:*:on-premises:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.