CVE-2022-3322

MEDIUM

Cloudflare WARP Mobile Client < 6.14 - Missing Authorization for Lock Warp Switch Bypass

Title source: llm
STIX 2.1

Description

Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action.

References (1)

Core 1

Scores

CVSS v3 6.7
EPSS 0.0025
EPSS Percentile 15.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862 CWE-347
Status published
Products (1)
cloudflare/warp_mobile_client < 6.14
Published Oct 28, 2022
Tracked Since Feb 18, 2026