CVE-2022-3337

It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the  Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature
 being enabled on Zero Trust Platform. This led to bypassing policies 
and restrictions enforced for enrolled devices by the Zero Trust 
platform.



ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:L
cloudflareCNA
6.7 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:L
CVEADP
---
---
CISA-ADPADP
---
---