Zero Trust Secure Web Gateway policies bypass using WARP client subcommands
CVE-2022-2225

8.1HIGH

Key Information:

Vendor

Cloudflare

Status
Vendor
CVE Published:
26 July 2022

What is CVE-2022-2225?

By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies) and features such as 'Lock WARP switch'.

Affected Version(s)

WARP Linux < 2022.5.346

WARP MacOS < 2022.5.227.0

WARP Windows < 2022.5.341.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.