Impact
A configuration interface in the Kiteworks appliance does not enforce authentication once initial setup is finished. An attacker who can reach the appliance over the network can read and modify a limited number of configuration entries—including the contact name and email address collected during the first configuration. This flaw allows an unauthenticated user to alter critical settings, potentially extending their reach into the system or facilitating further compromise.
Affected Systems
Kiteworks Core products are affected. The vulnerability applies to all versions of the appliance that expose the post‑initial‑configuration setup interface.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. EPSS information is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploits yet. The attack requires network access to the appliance and no authentication, making it straightforward for an attacker with connectivity to the device to exploit the flaw by reading or changing setup records.
OpenCVE Enrichment