logo

Critical Vulnerability: SysAid CVE-2023-47246

ID: 32331f76-16d7-5b90-a675-821b7647f28a

STIX ID: report--32331f76-16d7-5b90-a675-821b7647f28a

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

**Executive Summary:** Huntress details a critical path‑traversal RCE in SysAid on‑prem servers (CVE-2023-47246) that allows attackers to write WAR webshells to the Tomcat webroot and gain code execution; the activity is attributed to the cl0p/TA505 ransomware group, a weaponized proof‑of‑concept was developed (not released), and Huntress observed at least one active compromise while urging immediate patching to SysAid Server 23.3.36 and deploying detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.