EXPOSURES › CVE-2023-47246
CVE-2023-47246
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSysAid Server's path traversal flaw allowed remote code execution, directly enabling ransomware attacks.
SysAid Server's on-premises version suffered a path traversal vulnerability that led to remote code execution, a flaw actively exploited in the wild and linked to ransomware. DIB organizations must ensure all on-premises software is patched against known CVEs to prevent similar compromises. This failure highlights the risk of relying on unpatched software, even in controlled environments.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, demonstrating severe negligence in patching and security hygiene.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.