CVE-2022-3321: Lock WARP switch feature bypass on WARP mobile client for iOS
It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch on the WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings. Such configuration caused the WARP client to disconnect and allowed the user to bypass restrictions and policies enforced by the Zero Trust platform.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3321.
What is the severity of CVE-2022-3321?
The severity of CVE-2022-3321 is high with a severity value of 8.2.
How can the Lock WARP switch feature be bypassed?
The Lock WARP switch feature can be bypassed by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once on the WARP iOS mobile client.
What is the affected software of CVE-2022-3321?
The affected software of CVE-2022-3321 is the Cloudflare Warp Mobile Client version up to 6.14 on iPhone OS.
How can I fix the vulnerability in the Cloudflare Warp Mobile Client?
To fix the vulnerability, make sure to update the Cloudflare Warp Mobile Client to a version higher than 6.14.