CrowdSec
2/10CrowdSec Score

SysAid On-Prem - XXE (CVE-2025-2775)

Published on07-05-2025
First seen on07-06-2025

21Exploiting IPs reported

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

CrowdSec analysis

CVE-2025-2775 is a serious vulnerability in SysAid On-Prem that exposes systems to unauthenticated XML External Entity (XXE) attacks during check-in processing, potentially enabling attackers to read arbitrary files or take over administrator accounts.

CrowdSec has been tracking this vulnerability and its exploits since 1st of June 2025.

Based on data from the CrowdSec network, nearly all observed exploitation of CVE-2025-2775 is fully opportunistic, with attackers indiscriminately scanning the entire internet. These attacks are automated and lack any form of target selection or reconnaissance. In addition, according to the CrowdSec network, attack volume against CVE-2025-2775 has dipped slightly compared to the previous week. Although still commonly targeted, the decline suggests a cooling-off period. Long-term relevance remains, but attention is waning.

Exploitation attempts are characterized by requests to URLs containing /mdm/checkin.

Exploitation

Get real-time information about exploitation attempts and actors involved.

Detected IPs

Discover the IPs that targeted this vulnerability across the CrowdSec Network.

Protection

Find out relevant information to protect your stack against this CVE.

Blocklist

With our advanced worldwide network detection, CrowdSec can provide a list of IPs known for exploiting the vulnerability.

To increase your protection against this CVE, block exploitation attempts with this list of identified actors.