logo

CVE-2025-2775

ID: b2a71f61-b3ed-5172-8915-ec657f784a29

STIX ID: report--b2a71f61-b3ed-5172-8915-ec657f784a29

Feed Name: Arctic Wolf Blog

Threat Score
78/100

Date Published: 2025-05-07

Date Updated: 2026-04-27

...
...

On May 7, 2025, watchTowr published technical details and a public PoC for pre-authenticated XXE vulnerabilities (CVE-2025-2775/2776/2777) and a post-authentication command injection (CVE-2025-2778) in SysAid On-Premises that can be chained to achieve remote code execution and extract the main administrator’s clear-text password; fixes are available in SysAid 24.4.60 and later, and the report notes prior exploitation (Cl0p ransomware) of a SysAid zero-day in 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.