Impact
A resource exhaustion flaw in Kiteworks Email Protection Gateway enables an unauthenticated attacker to repeatedly initiate an expensive server‑side process, draining server resources and leading to a partial denial of service. The weakness lies in lacking proper input validation and missing rate‑limiting controls, which allow the attack to succeed without authentication.
Affected Systems
The vulnerability affects Kiteworks Email Protection Gateway. Specific affected versions are not disclosed in the advisory.
Risk and Exploitability
The exploit runs over the network; no credentials are required. The CVSS score of 5.3 indicates a medium severity vulnerability. The EPSS is unavailable and it is not catalogued in CISA’s KEV list, indicating limited publicly known exploitation. Nevertheless, because it can degrade service availability, operators should treat it as a significant risk worth addressing promptly.
OpenCVE Enrichment