Impact
An unauthenticated attacker can upload a file with attacker-controlled content to the appliance filesystem through an administrative upload handler that does not require authentication. The vulnerability allows write access to arbitrary files but does not directly succeed in executing code; execution would require a separate flaw that places a file in an executable location. The weakness corresponds to improper authentication (CWE-306) and improper file type validation (CWE-434).
Affected Systems
Kiteworks Email Protection Gateway is affected by this issue. No specific version information is listed in the advisory.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based administrative upload action that lacks authentication controls. An attacker can exploit this by sending a crafted file through the exposed upload endpoint, potentially compromising integrity and confidentiality of the appliance files.
OpenCVE Enrichment