ZeroHour

CVE-2022-3337

CVSS 3.1
8.5 high
EPSS
<1%p33
Published
()
Modified
Description

It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.

Vendors
cloudflare
Products
warp mobile client
Weakness
CWE-862, CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.