Medium severity5.9NVD Advisory· Published Oct 10, 2018· Updated Jun 17, 2026
CVE-2018-16758
CVE-2018-16758
Description
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:starwindsoftware:starwind_virtual_san:v8:build12533:*:*:*:vsphere:*:*+ 1 more
- cpe:2.3:a:starwindsoftware:starwind_virtual_san:v8:build12533:*:*:*:vsphere:*:*
- cpe:2.3:a:starwindsoftware:starwind_virtual_san:v8:build12658:*:*:*:vsphere:*:*
Patches
Vulnerability mechanics
References
4- tinc-vpn.org/security/nvdVendor Advisory
- www.debian.org/security/2018/dsa-4312nvdThird Party Advisory
- www.starwindsoftware.com/security/sw-20190227-0003/nvdThird Party Advisory
- www.tinc-vpn.org/git/browsenvd
News mentions
0No linked articles in our index yet.