VYPR

WARP

by Cloudflare

CVEs (6)

  • CVE-2025-0651HigJan 22, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges  can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After triggering the 'Reset all settings" option…

  • CVE-2022-3337MedOct 28, 2022
    risk 0.44cvss 6.7epss 0.00

    It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  feature being enabled on Zero Trust…

  • CVE-2022-3322MedOct 28, 2022
    risk 0.44cvss 6.7epss 0.00

    Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action.

  • CVE-2022-2147MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.00

    Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code execution leading to privilege escalation. The fix was released in version 2022.3.186.0.

  • CVE-2023-3747MedSep 7, 2023
    risk 0.36cvss 5.5epss 0.00

    Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Administrators to allow a device to temporarily be disconnected from WARP, however, due to lack of server side validation, an attacker…

  • CVE-2023-0238LowAug 29, 2023
    risk 0.25cvss 3.9epss 0.00

    Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability which allowed a malicious app installed on a victim's device to exploit a peculiarity in an Android function, wherein under certain conditions, the malicious app…