CVE-2022-3512
HIGHCVSS 8.8/10EPSS 0.39%
Last modified
CVE-2022-3512 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced on an affected endpoint. . EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced on an affected endpoint.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cloudflare | Warp | < 2022.8.857.0 |
| Cloudflare | Warp | < 2022.8.861.0 |
| Cloudflare | Warp | < 2022.8.936 |
References
- https://github.com/cloudflare/advisories/security/advisories/GHSA-3868-hwjx-r5xfThird Party Advisory
- https://github.com/cloudflare/advisories/security/advisories/GHSA-3868-hwjx-r5xfThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3512?
Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced on an affected endpoint.
How severe is CVE-2022-3512?
CVE-2022-3512 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.39% probability of exploitation in the next 30 days.
How do I fix CVE-2022-3512?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-35111SWFTools commit 772e55a2 was discovered to contain a stack o…5.5
- CVE-2022-35113SWFTools commit 772e55a2 was discovered to contain a heap-bu…5.5
- CVE-2022-35114SWFTools commit 772e55a2 was discovered to contain a segment…5.5
- CVE-2022-35115IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was disc…9.8
- CVE-2022-35117Clinic's Patient Management System v1.0 was discovered to co…4.8
- CVE-2022-35118PyroCMS v3.9 was discovered to contain multiple cross-site s…6.1
- CVE-2022-35120IXPdata EasyInstall 6.6.14725 contains an access control iss…8.8
- CVE-2022-35121Novel-Plus v3.6.1 was discovered to contain a SQL injection …9.8
- CVE-2022-35122An access control issue in Ecowitt GW1100 Series Weather Sta…9.1
- CVE-2022-3513An issue has been discovered in GitLab affecting all version…6.1
- CVE-2022-35131Joplin v2.8.8 allows attackers to execute arbitrary commands…9
- CVE-2022-35132Usermin through 1.850 allows a remote authenticated user to …8.8
Are you affected by CVE-2022-3512?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
