CyberRota Analysis
AI-GeneratedThe Kiteworks Email Protection Gateway has an identity-verification vulnerability that allows an unauthenticated remote sender to impersonate a legitimate user and provision a new account on the Kiteworks platform. This could lead to unauthorized access and control over platform accounts, posing a significant risk to user data and system integrity. Organizations using Kiteworks should prioritize addressing this vulnerability to safeguard their email communications and user accounts.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.