VYPR

TURN server

by Coturn

CVEs (2)

  • CVE-2018-4059CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.02

    An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can provide administrator access to the TURN…

  • CVE-2018-4058HigMar 21, 2019
    risk 0.50cvss 7.7epss 0.01

    An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5.0.9. By default, the TURN server allows relaying external traffic to the loopback interface of its own host. This can provide access to other private services…