CVE-2022-3321
Lock WARP switch feature bypass on WARP mobile client for iOS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch on the WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings. Such configuration caused the WARP client to disconnect and allowed the user to bypass restrictions and policies enforced by the Zero Trust platform.
Fue posible omitir la función de interruptor Lock WARP https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch en el cliente móvil WARP iOS habilitando ambos Los cambios ""Disable for cellular networks"" y ""Disable for Wi-Fi networks"" a la vez en la configuración de la aplicación. Dicha configuración provocó que el cliente WARP se desconectara y permitió al usuario eludir las restricciones y políticas impuestas por la plataforma Zero Trust.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-26 CVE Reserved
- 2022-10-28 CVE Published
- 2024-05-20 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
- CAPEC-122: Privilege Abuse
- CAPEC-554: Functionality Bypass
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/cloudflare/advisories/security/advisories/GHSA-4463-5p9m-3c78 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cloudflare Search vendor "Cloudflare" | Warp Mobile Client Search vendor "Cloudflare" for product "Warp Mobile Client" | < 6.14 Search vendor "Cloudflare" for product "Warp Mobile Client" and version " < 6.14" | iphone_os |
Affected
|