Warp
Vendor:
First CVE: Feb 3, 2021 · Active for 5 years
19
Total CVEs
More Total CVEs than 93% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Warp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2021
5 years ago
Most Recent CVE
Jan 22, 2025
547 days ago
CVE Severity & Scoring
Warp19 CVEs
21%
68%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (52.6%)
Network8 (42.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None15 (78.9%)
Unknown0 (0.0%)
Required4 (21.1%)
Privileges Required
Low12 (63.2%)
High0 (0.0%)
None7 (36.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3320CRITICAL It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint | Oct 28, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-3512HIGH Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced o | Oct 28, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-3337HIGH It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connection | Oct 28, 2022 | 8.5 | 27 | NO | NO |
CVE-2022-4428HIGH support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the | Jan 11, 2023 | 8.0 | 26 | NO | NO |
CVE-2022-3321HIGH It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch on the WARP i | Oct 28, 2022 | 8.2 | 26 | NO | NO |
CVE-2022-3322HIGH Lock Warp switch is a feature of Zero Trust platform which, when
enabled, prevents users of enrolled devices from disabling WARP client.
Due to insufficient policy verification b | Oct 28, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-2225HIGH By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure W | Jul 26, 2022 | 7.8 | 25 | NO | NO |
CVE-2023-0652HIGH Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a malicious | Apr 6, 2023 | 7.8 | 24 | NO | NO |
CVE-2022-2145HIGH Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder. During installation of the WARP client, it was possible to | Jun 28, 2022 | 7.8 | 24 | NO | NO |
CVE-2023-1412HIGH An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to perform privileged operations | Apr 5, 2023 | 7.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Warp
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.29 | 1 | 5.5 | 0.2% | 0 | 0 |