Description
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4312-1 | tinc security update |
EUVD |
EUVD-2018-8558 | Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:32:53.975Z
Reserved: 2018-09-09T00:00:00.000Z
Link: CVE-2018-16758
No data.
Status : Modified
Published: 2018-10-10T21:29:02.103
Modified: 2024-11-21T03:53:17.657
Link: CVE-2018-16758
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD