Tinc is a lightweight virtual private network daemon designed for secure mesh networking and point-to-point connectivity, with its vulnerability surface concentrated in the core tinc product itself. The limited observed disclosures reflect the product's narrow scope, though defenders deploying tinc in sensitive network architectures should monitor updates for the authentication and cryptographic mechanisms underlying its VPN functionality; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinc over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1755MEDIUM tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the da | Dec 31, 2002 | 5.0 | 15 | NO | NO |
CVE-2001-1505MEDIUM tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets. | Dec 31, 2001 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinc.
Media articles that mention a CVE ID that affects a product developed by Tinc — matched by CVE ID, not by vendor name.