Security Advisory

CVE-2022-3337

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-10-28 09:25:31
Last updated 2025-05-06 17:41:15
Assigner cloudflare
CVSS score 6.7
State PUBLISHED

Description

It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.