CVE-2022-3337
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/10/2022
Last modified:
07/11/2023
Description
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature<br />
being enabled on Zero Trust Platform. This led to bypassing policies <br />
and restrictions enforced for enrolled devices by the Zero Trust <br />
platform.<br />
<br />
<br />
<br />
Impact
Base Score 3.x
8.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cloudflare:warp_mobile_client:*:*:*:*:*:iphone_os:*:* | 6.15 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



