Impact
The vulnerability exists in an endpoint used only during the very first activation of a Kiteworks appliance. Because the endpoint performs no authentication verification and fails to enforce the expected precondition state, an unauthenticated attacker could repeatedly trigger the privileged activation process. This leads to an incomplete or unstable appliance configuration, effectively disrupting setup and causing denial of service to legitimate administrators.
Affected Systems
The affected vendor is Kiteworks, specifically the Core appliance. Product versions are not listed in the advisory, but the flaw applies to any instance undergoing initial activation for the first time and not yet fully configured.
Risk and Exploitability
The CVSS score of 5.9 places the issue in the moderate severity band. No EPSS figure is provided, and the vulnerability is not currently catalogued in CISA KEV. The attack can only occur while the appliance is in its activation window, but an attacker who can reach the network exposed setup endpoint can repeatedly invoke the vulnerable process. The limited scope of exposure reduces the overall risk, yet the ability to disrupt the entire setup process justifies an urgent patch.
OpenCVE Enrichment