Impact
Kiteworks Core is vulnerable to OS Command Injection because configuration packages are not properly validated when an authenticated administrator uploads them. A crafted package can cause the underlying operating system to execute arbitrary commands, potentially with elevated privileges, leading to full system compromise. This flaw threatens confidentiality, integrity, and availability of the affected appliance.
Affected Systems
Kiteworks Core appliances running any version prior to 9.5.0 are impacted. The vulnerability applies to all deployed installations that allow authenticated administrators to upload configuration packages.
Risk and Exploitability
The vulnerability has a CVSS score of 7.2, indicating high severity. No EPSS data is available, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated administrator account and the ability to upload a configuration package, so the attack vector is internal, though it can be leveraged remotely by compromising an administrator’s credentials.
OpenCVE Enrichment