Kiteworks MFT
cpe:2.3:a:accellion:kiteworks_managed_file_transfer:*:*:*:*:*:*:*
- < 9.1.0
A vulnerability exists in Kiteworks MFT versions prior to 9.1.0, where an incorrectly specified destination in a communication channel allows an attacker with administrative privileges to intercept upstream communications. This interception could lead to unauthorized privilege escalation.
Exploitation of this vulnerability could allow an attacker with administrative privileges to intercept communications and escalate privileges further.
Users are advised to upgrade Kiteworks MFT to version 9.1.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.