Cloudflare WARP(Cloudflare Vpn)是美国Cloudflare公司的一个用于安全连接的客户端应用软件。 Cloudflare WARP Zero Trust Secure Web Gateway存在安全漏洞,该漏洞源于攻击者通过warp-cli “add-trusted-ssid”子命令可以断开WARP客户端并绕过“锁定WARP开关”功能,导致在受影响的端点上不执行零信任策略。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cloudflare | WARP | 0 ~ 2022.8.857 | - |
|
| Cloudflare | WARP | 0 ~ 2022.8.936 | - |
|
| Cloudflare | WARP | 0 ~ 2022.8.861 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-3320 | 6.7 MEDIUM | Bypassing Cloudflare Zero Trust policies using warp-cli set-custom-endpoint command |
| CVE-2022-3321 | 6.7 MEDIUM | Lock WARP switch feature bypass on WARP mobile client for iOS |
| CVE-2022-3322 | 6.7 MEDIUM | Lock WARP switch bypass on WARP mobile client using iOS quick action |
| CVE-2022-3337 | 6.7 MEDIUM | Lock WARP switch bypass by removing VPN profile on iOS mobile client |
| CVE-2022-3616 | 5.4 MEDIUM | OctoRPKI crash when maximum iterations number is reached |
No comments yet