CVE-2023-3747 Vulnerability Details

  /     /     /  

CVE-2023-3747 Metadata Quick Info

CVE Published: 07/09/2023 | CVE Updated: 26/09/2024 | CVE Year: 2023
Source: cloudflare | Vendor: Cloudflare | Product: WARP Client
Status : PUBLISHED

CVE-2023-3747 Description

Zero Trust Administrators have the ability to disallow end users from disabling WARP on their devices. Override codes can also be created by the Administrators to allow a device to temporarily be disconnected from WARP, however, due to lack of server side validation, an attacker with local access to the device, could extend the maximum allowed disconnected time of WARP client granted by an override code by changing the date & time on the local device where WARP is running.

Metrics

CVSS Version: 3.1 | Base Score: 5.5 MEDIUM
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* NONE
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-602
CWE Name: CWE-602
Source: Cloudflare

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-207
CAPEC Description: CAPEC-207 Removing Important Client Functionality


Source: NVD (National Vulnerability Database).