Tinc is a lightweight open-source mesh VPN implementation that enables peer-to-peer encrypted networking across distributed nodes, with its vulnerability footprint concentrated in the single tinc daemon application. The observed disclosures reflect the complexity inherent to VPN protocol parsing and cryptographic state management; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinc Vpn over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-1428MEDIUM Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of se | Apr 26, 2013 | 6.5 | 67 | NO | YES |
CVE-2018-16758MEDIUM Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets. | Oct 10, 2018 | 5.9 | 22 | NO | NO |
CVE-2018-16737MEDIUM tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation. | Oct 10, 2018 | 5.3 | 21 | NO | NO |
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1. | Oct 10, 2018 | 3.7 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinc Vpn.
Media articles that mention a CVE ID that affects a product developed by Tinc Vpn — matched by CVE ID, not by vendor name.