PT-2022-21776 · Cloudflare · Cloudflare Warp
Josh
+1
·
Published
2022-10-28
·
Updated
2022-11-01
·
CVE-2022-3337
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Cloudflare WARP mobile client (affected versions not specified)
Description
The issue allowed a user to delete a VPN profile from the WARP mobile client on the iOS platform, despite the Lock WARP switch feature being enabled on the Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloudflare Warp