Impact
A Kiteworks Core appliance setup interface failed to constrain a user‑supplied file path; an unauthenticated attacker could write a file to any writable location under the service account, potentially overwriting critical files or installing malicious payloads, which may lead to integrity compromise or service disruption; this vulnerability is a directory traversal flaw (CWE-22).
Affected Systems
The vulnerability affects Kiteworks Core appliances; the exact product name is Kiteworks Core, and no specific version details are provided in the advisory.
Risk and Exploitability
The CVSS score of 7.4 indicates a high risk, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires network access to the setup interface, which is normally not exposed by a fully configured appliance; attackers would need to target the transient provisioning window or a non‑default configuration that exposes the interface.
OpenCVE Enrichment