Lucene search

K
cveCloudflareCVE-2023-0654
HistoryAug 29, 2023 - 4:15 p.m.

CVE-2023-0654

2023-08-2916:15:08
CWE-1021
cloudflare
web.nvd.nist.gov
28
cve-2023-0654
misconfiguration
warp mobile client
android
tapjacking
vulnerability
security bug

CVSS3

3.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

AI Score

4.1

Confidence

High

EPSS

0.001

Percentile

21.6%

Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the event that an attacker built a malicious application and managed to install it on a victim’s device, the attacker would be able to trick the user into believing that the app shown on the screen was the WARP client when in reality it was the attacker’s app.

Affected configurations

Nvd
Node
cloudflarewarpRange<6.29android
VendorProductVersionCPE
cloudflarewarp*cpe:2.3:a:cloudflare:warp:*:*:*:*:*:android:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Android"
    ],
    "product": "WARP Client",
    "vendor": "Cloudflare",
    "versions": [
      {
        "changes": [
          {
            "at": "6.29",
            "status": "unaffected"
          }
        ],
        "lessThan": "6.29",
        "status": "affected",
        "version": "0",
        "versionType": "patch"
      }
    ]
  }
]

CVSS3

3.9

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

AI Score

4.1

Confidence

High

EPSS

0.001

Percentile

21.6%