Cloudflare WARP(Cloudflare Vpn)是美国Cloudflare公司的一个用于安全连接的客户端应用软件。 Cloudflare WARP存在安全漏洞,该漏洞源于尽管在零信任平台上启用了锁定WARP开关功能,但用户可以从iOS平台上的WARP移动客户端中删除VPN配置文件。这导致绕过零信任平台对已注册设备强制实施的策略和限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cloudflare | WARP | 0 ~ 6.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-3320 | 6.7 MEDIUM | Bypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint command |
| CVE-2022-3321 | 6.7 MEDIUM | Lock WARP switch feature bypass on WARP mobile client for iOS |
| CVE-2022-3322 | 6.7 MEDIUM | Lock WARP switch bypass on WARP mobile client using iOS quick action |
| CVE-2022-3512 | 6.7 MEDIUM | Lock WARP switch bypass using warp-cli 'add-trusted-ssid' command |
| CVE-2022-3616 | 5.4 MEDIUM | OctoRPKI crash when maximum iterations number is reached |
No comments yet