VDB

CVE-2018-4058

CVE-2018-4058 PUBLISHED

An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5.0.9. By default, the TURN server allows relaying external traffic to the loopback interface of its own host. This can provide access to other private services running on that host, which can lead to further attacks. An attacker can set up a relay with a loopback address as the peer on an affected TURN server to trigger this vulnerability.

EPSS 0.18% · 38.8th percentile

Risk Scores

EPSS Score
0.18%
38.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTScoturn0, 4.4.5.4-2, 4.5.0.2-3
Ubuntu:18.04:LTScoturn4.5.0.6-1ubuntu2, 4.5.0.7-1ubuntu1, 4.5.0.7-1ubuntu2

Timeline

  • CVE Published
  • Jan 30, 2019 PoC Published
  • Apr 13, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›