← Vulnerability feed

Vulnerability record · CVE-2018-16737 · published 10 October 2018

CVE-2018-16737: Tinc-vpn tinc improper authentication vulnerability

Tinc Vpn · Tinc

tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.

5.3 CVSS 3.1 Medium EPSS 1.5% · top 27.3% CWE-287 · Improper authentication
5.3CVSS 3.1 base score, v2 5.0
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-16737 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-4034polkit pkexec argument handling flaw allows local root escalationpkexec, the setuid polkit utility for running commands as privileged users, mishandles the calling parameter count and ends up treating environment v…KEVEPSS 94%analysed9.8CVE-2021-43527Mozilla nss out-of-bounds write vulnerabilityNSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signa…EPSS 18%8.8CVE-2018-3839Libsdl sdl image out-of-bounds write vulnerabilityAn exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially…EPSS 2.6%8.3CVE-2021-42574Unicode code injection vulnerabilityAn issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via …EPSS 13%7.8CVE-2020-36385Linux kernel use after free vulnerabilityAn issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_l…EPSS 1.5%7.8CVE-2020-14409Libsdl simple directmedia layer integer overflow vulnerabilitySDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_co…EPSS 1.3%7.2CVE-2020-25643Linux kernel improper input validation vulnerabilityA flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper i…EPSS 3.3%7.1CVE-2020-24394Linux kernel incorrect permission assignment vulnerabilityIn the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2018-16737), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.