CVE-2022-3337
Lock WARP switch bypass by removing VPN profile on iOS mobile client
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature
being enabled on Zero Trust Platform. This led to bypassing policies
and restrictions enforced for enrolled devices by the Zero Trust
platform.
Un usuario podía eliminar un perfil VPN del cliente móvil WARP en la plataforma iOS a pesar del interruptor Lock WARP https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/# La función lock-warp-switch está habilitada en Zero Trust Platform. Esto llevó a eludir las políticas y restricciones impuestas a los dispositivos inscritos por la plataforma Zero Trust.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-27 CVE Reserved
- 2022-10-28 CVE Published
- 2024-05-20 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-290: Authentication Bypass by Spoofing
- CWE-862: Missing Authorization
CAPEC
- CAPEC-122: Privilege Abuse
- CAPEC-554: Functionality Bypass
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/cloudflare/advisories/security/advisories/GHSA-vr93-4vx7-332p | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cloudflare Search vendor "Cloudflare" | Warp Mobile Client Search vendor "Cloudflare" for product "Warp Mobile Client" | < 6.15 Search vendor "Cloudflare" for product "Warp Mobile Client" and version " < 6.15" | iphone_os |
Affected
|