Impact
Kiteworks Email Protection Gateway versions before 9.5.0 contain an SSRF weakness. The vulnerability is exercised while the gateway fetches a certificate revocation list from an inbound message; a crafted request can cause the gateway to issue requests to internal or otherwise unintended network destinations. The attacker gains the ability to read sensitive internal data or disrupt gateway operation, but does not achieve local code execution on the gateway itself. This flaw is identified as CWE‑918.
Affected Systems
The affected product is Kiteworks Email Protection Gateway. All releases older than version 9.5.0 are impacted. No further details on patch levels are provided.
Risk and Exploitability
The CVSS score of 9.1 categorizes the issue as high‑severity. Because the vulnerability allows arbitrary outbound traffic, it can be leveraged against any service reachable from the gateway, potentially exposing internal addresses and data. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that no publicly known exploits are currently documented. The likely attack vector is via a crafted inbound email that triggers CRL retrieval, thus requiring the attacker to be able to send such an email to the gateway.
OpenCVE Enrichment