It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature
being enabled on Zero Trust Platform. This led to bypassing policies
and restrictions enforced for enrolled devices by the Zero Trust
platform.
being enabled on Zero Trust Platform. This led to bypassing policies
and restrictions enforced for enrolled devices by the Zero Trust
platform.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42724 | It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform. |
Fixes
Solution
Upgrade to specified patched version.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: cloudflare
Published:
Updated: 2025-05-06T17:41:15.374Z
Reserved: 2022-09-27T10:25:13.653Z
Link: CVE-2022-3337
Updated: 2024-08-03T01:07:06.580Z
Status : Modified
Published: 2022-10-28T10:15:17.563
Modified: 2024-11-21T07:19:19.430
Link: CVE-2022-3337
No data.
OpenCVE Enrichment
No data.
EUVD