CVE-2018-16758

Severity
5.9MEDIUM
EPSS
0.2%
top 62.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateMay 13

Description

Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

Debiantinc< 1.0.35-1+3
NVDtinc-vpn/tinc1.0.34

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-52p3-pmr5-f54r: Missing message authentication in the meta-protocol in Tinc VPN version 12022-05-13
OSV
CVE-2018-16758: Missing message authentication in the meta-protocol in Tinc VPN version 12018-10-10
CVEList
CVE-2018-16758: Missing message authentication in the meta-protocol in Tinc VPN version 12018-10-10

📋Vendor Advisories

1
Debian
CVE-2018-16758: tinc - Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 a...2018

💬Community

3
Bugzilla
CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release2018-10-09
Bugzilla
CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release [fedora-all]2018-10-09
Bugzilla
CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release [epel-all]2018-10-09