Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in Kiteworks Email Protection Gateway, allowing unauthenticated attackers to potentially send crafted requests from the gateway to internal or unintended network destinations. This could lead to the disclosure of sensitive internal information or disruption of gateway operations, depending on the network services accessible by the gateway.
- Attackers can trick the gateway into sending requests.
- This bypasses network controls for sensitive data.
- Confirm if your email gateway is affected.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by sending a specially crafted inbound message to the Kiteworks Email Protection Gateway. This message will cause the gateway to retrieve a certificate revocation list, during which process it can be tricked into sending requests to internal network destinations. This can lead to the disclosure of sensitive information or disruption of the gateway's operations.
- No authentication or user interaction needed.
- Triggered during certificate revocation list retrieval.
- Can expose internal information or disrupt services.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated attacker to trick the Kiteworks Email Protection Gateway into sending requests to internal network locations. This could expose sensitive internal data or disrupt the gateway's normal functioning, depending on what services are accessible from the gateway.
- Internal network information could be exposed.
- Crafted requests could be sent to unintended destinations.
- Gateway operations may be disrupted.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Kiteworks Email Protection Gateway, an internet-facing appliance, is vulnerable to SSRF attacks. This could allow unauthenticated remote attackers to trigger crafted requests to internal systems, potentially disclosing sensitive information or disrupting operations. Ownership typically falls to the platform or infrastructure team managing the gateway, in coordination with security and vendor management. The first practical step is to identify all instances of the affected technology, assess their exposure and business criticality, and confirm the accountable owner to plan remediation based on risk.
- Platform or infrastructure teams own.
- Verify gateway reachability and criticality.
- Plan remediation based on exposure.