CVE-2022-3337
This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.
- CVSS 3.1
- 8.5 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862, CWE-290
- Affected
- cloudflare/warp mobile client
- Source
- cna@cloudflare.com
References
- https://github.com/cloudflare/advisories/security/advisories/GHSA-vr93-4vx7-332pThird Party Advisory
- https://github.com/cloudflare/advisories/security/advisories/GHSA-vr93-4vx7-332pThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.