CVE-2018-16758
Severity
5.9MEDIUM
EPSS
0.2%
top 62.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 10
Latest updateMay 13
Description
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6
Affected Packages3 packages
Also affects: Debian Linux 9.0
🔴Vulnerability Details
3GHSA▶
GHSA-52p3-pmr5-f54r: Missing message authentication in the meta-protocol in Tinc VPN version 1↗2022-05-13
OSV▶
CVE-2018-16758: Missing message authentication in the meta-protocol in Tinc VPN version 1↗2018-10-10
CVEList▶
CVE-2018-16758: Missing message authentication in the meta-protocol in Tinc VPN version 1↗2018-10-10
📋Vendor Advisories
1Debian▶
CVE-2018-16758: tinc - Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 a...↗2018
💬Community
3Bugzilla▶
CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release↗2018-10-09
Bugzilla▶
CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release [fedora-all]↗2018-10-09
Bugzilla▶
CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release [epel-all]↗2018-10-09