CVE-2018-16737: Medium severity tinc vpn vulnerability
tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16737?
CVE-2018-16737 is a vulnerability in the tinc VPN software before version 1.0.30 that allows for a broken authentication protocol without any partial mitigation.
How severe is CVE-2018-16737?
CVE-2018-16737 has a severity rating of 5.3 (medium).
How can I fix CVE-2018-16737?
To fix CVE-2018-16737, you should update your tinc VPN software to version 1.0.30 or newer.
Where can I find more information about CVE-2018-16737?
You can find more information about CVE-2018-16737 at the following references: [http://tinc-vpn.org/security/](http://tinc-vpn.org/security/), [http://www.tinc-vpn.org/git/browse?p=tinc;a=commit;h=d3297fbd3b8c8c8a4661f5bbf89aca5cacba8b5a](http://www.tinc-vpn.org/git/browse?p=tinc;a=commit;h=d3297fbd3b8c8c8a4661f5bbf89aca5cacba8b5a), [https://www.starwindsoftware.com/security/sw-20190227-0001/](https://www.starwindsoftware.com/security/sw-20190227-0001/)
What is the Common Weakness Enumeration (CWE) number for CVE-2018-16737?
CVE-2018-16737 is associated with CWE-287, which refers to an authentication error vulnerability.