CVE-2023-3747
MEDIUMCloudflare WARP - Client-Side Enforcement Bypass via Local Date Manipulation
Title source: llmDescription
Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Administrators to allow a device to temporarily be disconnected from WARP, however, due to lack of server side validation, an attacker with local access to the device, could extend the maximum allowed disconnected time of WARP client granted by an override code by changing the date & time on the local device where WARP is running.
References (2)
Core 2
Core References
Product release-notes
https://play.google.com/store/apps/details?id=com.cloudflare.onedotonedotonedotone
Scores
CVSS v3
5.5
EPSS
0.0018
EPSS Percentile
7.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-602
CWE-565
Status
published
Products (1)
cloudflare/warp
6.29
Published
Sep 07, 2023
Tracked Since
Feb 18, 2026