CVE-2016-2183

Sweet32 attack (DES, 3DES)

Description

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
99.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
95.7 %
High — model estimates ≥ 50% chance of real-world exploitation within 30 days.
Published
2016-09-01 00:00 UTC

Affected operating systems

  • linux

    redhat / enterprise_linux5.0

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • cisco

    content_security_management_appliance

  • nodejs

    node.js0.10.0 – 0.10.47

  • nodejs

    node.js0.12.0 – 0.12.16

  • nodejs

    node.js4.0.0 – 4.1.2

  • nodejs

    node.js4.2.0 – 4.6.0

  • nodejs

    node.js6.0.0 – 6.7.0

  • openssl

    openssl

  • oracle

    database

  • python

    python2.7.0 – 2.7.13

  • python

    python3.4.0 – 3.4.7

  • python

    python3.5.0 – 3.5.3

  • redhat

    jboss_enterprise_application_platform

  • redhat

    jboss_enterprise_web_server

  • redhat

    jboss_web_server

References & sources

IDCVE-2016-2183
Sweet32 attack (DES, 3DES) — CVE-2016-2183 | NEOSEC Intel