Vulnerability Details CVE-2022-3320
It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint caused the WARP Client to disconnect and allowed bypassing administrative restrictions on a Zero Trust enrolled endpoint.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.3%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2022-3320
-
cpe:2.3:a:cloudflare:warp:-
-
cpe:2.3:a:cloudflare:warp:1.2.1386
-
cpe:2.3:a:cloudflare:warp:1.2.1387
-
cpe:2.3:a:cloudflare:warp:1.2.1441
-
cpe:2.3:a:cloudflare:warp:1.2.1442
-
cpe:2.3:a:cloudflare:warp:1.2.1444
-
cpe:2.3:a:cloudflare:warp:1.2.1445
-
cpe:2.3:a:cloudflare:warp:1.2.1467
-
cpe:2.3:a:cloudflare:warp:1.2.1522
-
cpe:2.3:a:cloudflare:warp:1.2.1523
-
cpe:2.3:a:cloudflare:warp:1.2.1563
-
cpe:2.3:a:cloudflare:warp:1.2.1564
-
cpe:2.3:a:cloudflare:warp:1.2.1590
-
cpe:2.3:a:cloudflare:warp:1.2.1591
-
cpe:2.3:a:cloudflare:warp:1.2.1866
-
cpe:2.3:a:cloudflare:warp:1.2.1924
-
cpe:2.3:a:cloudflare:warp:1.2.1989
-
cpe:2.3:a:cloudflare:warp:1.2.2240
-
cpe:2.3:a:cloudflare:warp:1.2.2278
-
cpe:2.3:a:cloudflare:warp:1.2.2544.0
-
cpe:2.3:a:cloudflare:warp:1.2.2695.1
-
cpe:2.3:a:cloudflare:warp:1.2.2834.0
-
cpe:2.3:a:cloudflare:warp:1.2.2866.0
-
cpe:2.3:a:cloudflare:warp:1.3.184.0
-
cpe:2.3:a:cloudflare:warp:1.3.206
-
cpe:2.3:a:cloudflare:warp:1.3.58
-
cpe:2.3:a:cloudflare:warp:1.4.106
-
cpe:2.3:a:cloudflare:warp:1.4.107.0
-
cpe:2.3:a:cloudflare:warp:1.4.25.0
-
cpe:2.3:a:cloudflare:warp:1.4.27
-
cpe:2.3:a:cloudflare:warp:1.4.33.0
-
cpe:2.3:a:cloudflare:warp:1.4.34
-
cpe:2.3:a:cloudflare:warp:1.5.147.0
-
cpe:2.3:a:cloudflare:warp:1.5.148.0
-
cpe:2.3:a:cloudflare:warp:1.5.206.0
-
cpe:2.3:a:cloudflare:warp:1.5.207.0
-
cpe:2.3:a:cloudflare:warp:1.5.294.0
-
cpe:2.3:a:cloudflare:warp:1.5.295.0
-
cpe:2.3:a:cloudflare:warp:1.5.461.0
-
cpe:2.3:a:cloudflare:warp:1.5.463.0
-
cpe:2.3:a:cloudflare:warp:1.6.27.0
-
cpe:2.3:a:cloudflare:warp:1.6.28.0
-
cpe:2.3:a:cloudflare:warp:2021.11.155.0
-
cpe:2.3:a:cloudflare:warp:2021.11.276.0
-
cpe:2.3:a:cloudflare:warp:2021.11.281.0
-
cpe:2.3:a:cloudflare:warp:2021.12.1.0
-
cpe:2.3:a:cloudflare:warp:2021.12.2.0
-
cpe:2.3:a:cloudflare:warp:2022.2.247.0
-
cpe:2.3:a:cloudflare:warp:2022.2.248.0
-
cpe:2.3:a:cloudflare:warp:2022.2.69.0
-
cpe:2.3:a:cloudflare:warp:2022.2.95.0
-
cpe:2.3:a:cloudflare:warp:2022.3.186.0
-
cpe:2.3:a:cloudflare:warp:2022.3.187.0
-
cpe:2.3:a:cloudflare:warp:2022.3.36.0
-
cpe:2.3:a:cloudflare:warp:2022.3.63.0
-
cpe:2.3:a:cloudflare:warp:2022.4.114.0
-
cpe:2.3:a:cloudflare:warp:2022.4.115.0
-
cpe:2.3:a:cloudflare:warp:2022.5.226.0
-
cpe:2.3:a:cloudflare:warp:2022.5.227.0
-
cpe:2.3:a:cloudflare:warp:2022.5.309.0
-
cpe:2.3:a:cloudflare:warp:2022.5.310.0
-
cpe:2.3:a:cloudflare:warp:2022.5.341.0
-
cpe:2.3:a:cloudflare:warp:2022.5.342.0
-
cpe:2.3:a:cloudflare:warp:2022.7.174.0
-
cpe:2.3:a:cloudflare:warp:2022.7.175.0