Impact
A server‑side request forgery flaw exists in Kiteworks Email Protection Gateway prior to version 9.5.0. The vulnerability is triggered when the gateway retrieves an issuer certificate from an inbound message. An attacker who can send a crafted inbound message can cause the gateway to issue HTTP requests to internal or otherwise unintended network destinations. This could enable the disclosure of sensitive internal information or cause disruption of gateway operation.
Affected Systems
Kiteworks Email Protection Gateway. All installations running any version earlier than 9.5.0 are affected.
Risk and Exploitability
The CVSS score of 9.1 indicates that remote attackers can achieve significant impact without authentication. While an EPSS score is not available, the lack of authentication requirements and the potential for internal data leakage or service disruption make the risk high. The vulnerability is not currently listed in the CISA KEV catalog, but the severity and the possible attack path involve a remote, unauthenticated attacker exploiting the gateway’s request‑sending behavior to reach internal resources.
OpenCVE Enrichment