CVE-2018-1000159 affects tlslite-ng version 0.7.3 and earlier, stemming from an improper validation of integrity check value in its TLS implementation. This vulnerability allows a man-in-the-middle attacker to manipulate TLS ciphertext without detection by the receiving tlslite-ng instance. The vulnerability is rated Medium severity (CVSS 5.9), indicating a network-based attack with high impact on integrity but no impact on confidentiality or availability. The attack complexity is high, requiring specific conditions for successful exploitation. There is no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.7.3CPE matchmatch criteria | cpe:2.3:a:tlslite-ng_project:tlslite-ng:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.