PT-2022-21750 · Unknown · Warp Ios Client

Josh

+1

·

Published

2022-10-28

·

Updated

2022-10-31

·

CVE-2022-3322

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WARP iOS client (affected versions not specified)
Description The Lock Warp switch feature in the Zero Trust platform can be bypassed due to insufficient policy verification by the WARP iOS client. This bypass can be achieved by using the "Disable WARP" quick action, allowing users of enrolled devices to disable the WARP client even when the Lock Warp switch is enabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2022-3322
GHSA-76PG-RP9H-WMCJ

Affected Products

Warp Ios Client