CVE-2022-3337: Lock WARP switch bypass by removing VPN profile on iOS mobile client
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-3337?
CVE-2022-3337 is a vulnerability that allowed users to delete a VPN profile from the WARP mobile client on the iOS platform despite the Lock WARP switch being enabled.
How severe is CVE-2022-3337?
CVE-2022-3337 has a severity rating of 8.5, which is considered high.
How does CVE-2022-3337 affect Cloudflare WARP mobile client?
CVE-2022-3337 affects the Cloudflare WARP mobile client on iOS devices running versions up to and excluding 6.15.
How can I fix the vulnerability CVE-2022-3337?
To fix CVE-2022-3337, it is recommended to update your Cloudflare WARP mobile client to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2022-3337?
More information about CVE-2022-3337 can be found at the following reference: [link](https://github.com/cloudflare/advisories/security/advisories/GHSA-vr93-4vx7-332p)