NA

CVE-2022-3337

Published: 28/10/2022 Updated: 07/11/2023
CVSS v3 Base Score: 8.5 | Impact Score: 4.7 | Exploitability Score: 3.1
VMScore: 0

Vulnerability Summary

It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cloudflare warp mobile client