NA

CVE-2022-3321

Published: 28/10/2022 Updated: 07/11/2023
CVSS v3 Base Score: 8.2 | Impact Score: 4.2 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

It was possible to bypass Lock WARP switch feature developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  on the WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings. Such configuration caused the WARP client to disconnect and allowed the user to bypass restrictions and policies enforced by the Zero Trust platform.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cloudflare warp mobile client