{"id":"CVE-2018-16758","details":"Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.","modified":"2026-03-12T22:49:10.785479Z","published":"2018-10-10T21:29:02.103Z","related":["openSUSE-SU-2024:11463-1"],"references":[{"type":"WEB","url":"http://www.tinc-vpn.org/git/browse?p=tinc%3Ba=commit%3Bh=e97943b7cc9c851ae36f5a41e2b6102faa74193f"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4312"},{"type":"ADVISORY","url":"https://www.starwindsoftware.com/security/sw-20190227-0003/"},{"type":"ADVISORY","url":"http://tinc-vpn.org/security/"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"1.0.34"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"v8-build12533"}]},{"events":[{"introduced":"0"},{"last_affected":"v8-build12658"}]}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-16758.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}