PT-2022-15299 · Warp · Warp

Mskowroncf

·

Published

2022-07-26

·

Updated

2022-08-01

·

CVE-2022-2225

CVSS v3.1

8.1

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions WARP (affected versions not specified)
Description The issue allows a user without admin privileges to bypass configured Zero Trust security policies, such as Secure Web Gateway policies, and features like 'Lock WARP switch' by utilizing warp-cli subcommands like disable-ethernet and disable-wifi.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-2225
GHSA-CG88-VX48-976C

Affected Products

Warp