Impact
The Kiteworks Email Protection Gateway fails to enforce restrictions on which account a certificate may be assigned to. An attacker can thus associate a certificate with a different user’s account, compromising the confidentiality and integrity of that account’s encrypted mail. If certificate-based login is enabled, the compromised account can be accessed without legitimate credentials.
Affected Systems
Kiteworks Email Protection Gateway from Kiteworks. No specific product versions are listed in the advisories, so all released builds may be affected until a patch is applied.
Risk and Exploitability
The CVSS score is 9.4, indicating critical severity. EPSS is not available, so the likelihood of exploitation cannot be quantified, but the absence of a KEV listing does not diminish the potential impact. Based on the description, it is inferred that the vulnerability can be exercised through the gateway’s certificate management functions. The likely attack vector is any authenticated session that has rights to create certificates, through which an attacker can redirect a valid certificate to a target account and gain unauthorized access to that account’s encrypted communications and possibly its login session.
OpenCVE Enrichment