CVE-2023-0654 Vulnerability Details

  /     /     /  

CVE-2023-0654 Metadata Quick Info

CVE Published: 29/08/2023 | CVE Updated: 30/09/2024 | CVE Year: 2023
Source: cloudflare | Vendor: Cloudflare | Product: WARP Client
Status : PUBLISHED

CVE-2023-0654 Description

Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the event that an attacker built a malicious application and managed to install it on a victim\'s device, the attacker would be able to trick the user into believing that the app shown on the screen was the WARP client when in reality it was the attacker\'s app.

Metrics

CVSS Version: 3.1 | Base Score: 3.9 LOW
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* LOW
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-1021
CWE Name: CWE-1021 Improper Restriction of Rendered UI Layers or Frames
Source: Cloudflare

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-506
CAPEC Description: CAPEC-506 Tapjacking


Source: NVD (National Vulnerability Database).