Impact
An authenticated administrator can import configuration data that is not validated correctly, allowing execution of arbitrary commands on the gateway. The flaw exploits unsafe path handling (CWE-22) and code injection (CWE-94), which can lead to full compromise of the gateway and potentially connected services.
Affected Systems
The vulnerability affects Kiteworks Email Protection Gateway installations older than version 9.5.0. No other vendors or product lines are listed as impacted.
Risk and Exploitability
With a CVSS score of 7.2 the risk is considered high. The EPSS score is 1%, and the vulnerability is not listed in CISA's KEV catalog, indicating no publicly known exploitation yet. The attack requires privileged administrator access, so the likelihood of exploitation is reduced compared to an unauthenticated vector but remains significant in environments with unrestricted admin privileges.
OpenCVE Enrichment