CyberRota Analysis
AI-GeneratedThe Kiteworks Email Protection Gateway contains a critical vulnerability due to improper authentication in its administrative service, allowing attackers to bypass password checks for administrator accounts. This flaw enables unauthorized users to create, modify, or delete internal users and managed domains, potentially leading to significant security breaches, including locking legitimate administrators out of the system. Organizations using this gateway should prioritize immediate remediation to mitigate the risk of unauthorized access and data loss.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and change their security-feature configuration without authenticating; deleting a managed domain also removes its user accounts and could lock administrators out of the gateway.