CVE-2025-2775: PoC Released for SysAid On-Premises Pre-Auth RCE Vulnerability

Post Reply
Shane1145
Posts: 1289
Joined: Wed Sep 25, 2024 2:31 pm

CVE-2025-2775: PoC Released for SysAid On-Premises Pre-Auth RCE Vulnerability

Post by Shane1145 »

On May 7, 2025, watchTowr publicly disclosed technical details and a proof-of-concept (PoC) exploit for a pre-authenticated Remote Code Execution (RCE) chain affecting SysAid On-Premises, a self-hosted IT service management (ITSM) platform used by organizations to manage IT support tasks.
Although the vulnerabilities were patched in March 2025, they had not been assigned Common Vulnerabilities and Exposures (CVE) identifiers and were disclosed for the first time with watchTowr’s publication. Common Vulnerability Scoring System (CVSS) scores have not been assigned.

https://arcticwolf.com/resources/blog/cve-2025-2775/
Post Reply