Impact
An XML parser in Kiteworks Email Protection Gateway does not restrict external XML entity references. When the optional message‑processing feature is enabled, an unauthenticated sender can craft a message with a malicious XML payload that forces the gateway to resolve external entities. This allows the gateway service account to read arbitrary files, including cryptographic keys and credentials, and forward them to an attacker‑controlled address, thereby compromising sensitive data.
Affected Systems
All installations of Kiteworks Email Protection Gateway that have the optional message‑processing feature enabled. No specific version ranges are published, so any release containing the feature may be vulnerable.
Risk and Exploitability
The CVSS base score of 7 indicates high severity. Exploitation requires only remote delivery of a crafted message and does not need authentication. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high score and remote unauthenticated nature mean the risk is substantial, especially for systems with the feature active and exposed to untrusted email. Reducing the attack surface by disabling the feature or mitigating XML parsing can lower the threat level.
OpenCVE Enrichment