CVE-2016-2183
published 2016-09-01CVE-2016-2183: The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four…
PriorityP272high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EXPLOIT
EPSS
95.71%
99.9th percentile
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | content_security_management_appliance | — | — |
| cisco | content_security_management_appliance | — | — |
| github.com | kyverno_kyverno | >= 0 < 1.9.5 | 1.9.5 |
| mozilla | nss | >= 0 < 2:3.28.4-0ubuntu0.14.04.1 | 2:3.28.4-0ubuntu0.14.04.1 |
| mozilla | nss | >= 0 < 2:3.28.4-0ubuntu0.16.04.1 | 2:3.28.4-0ubuntu0.16.04.1 |
| nodejs | node.js | >= 0.10.0 < 0.10.47 | 0.10.47 |
| nodejs | node.js | >= 0.12.0 < 0.12.16 | 0.12.16 |
| nodejs | node.js | >= 4.0.0 < 4.1.2 | 4.1.2 |
| nodejs | node.js | >= 4.2.0 < 4.6.0 | 4.6.0 |
| nodejs | node.js | >= 6.0.0 < 6.7.0 | 6.7.0 |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect use of Triple DES (3DES) cipher in TLS/SSL sessions — a necessary precondition for SWEET32 exploitation. Flag any TLS negotiation selecting a 3DES-based cipher suite. ↗
- →Monitor for abnormally long-duration TLS/HTTPS sessions using 3DES in CBC mode, particularly those accumulating ~32 GB of encrypted traffic under the same key — the threshold needed for a successful birthday attack. ↗
- →Alert on unexpectedly large volumes of encrypted traffic on systems using older SSL/TLS versions with 3DES enabled, especially repetitive or automated long-lived sessions. ↗
- →Flag TCP port 1243 traffic using 3DES encryption — Tenable LCE was found errantly using 3DES on this port, making it a specific detection target for misconfigured 3DES usage. ↗
- →Use vulnerability scanners (e.g., Nessus) to flag SSL/TLS configurations advertising 3DES cipher suites. Review SIEM logs for long-duration encrypted sessions using insecure algorithms like 3DES. ↗
- ·CVE-2016-2183 (SWEET32) is a cryptographic weakness in 64-bit block ciphers (3DES/DES), not a memory corruption bug. Exploitation requires a passive MITM position and a long-duration session accumulating ~32 GB of ciphertext — it is not a trivial remote code execution. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
ghsa7.5HIGH
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_cisco5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
Red Hat
openshift: etcd grpc-proxy vulnerable to The Birthday attack against 64-bit block cipher
vendor_redhat·2023-01-16·CVSS 7.5
CVE-2023-0296 [HIGH] CWE-327 openshift: etcd grpc-proxy vulnerable to The Birthday attack against 64-bit block cipher
openshift: etcd grpc-proxy vulnerable to The Birthday attack against 64-bit block cipher
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary to open up a new port (9979) on etcd grpc-proxy, hence this port might be considered as still vulnerable to the same type of vulnerability. The health checks on etcd grpc-proxy do not contain sensitive data (only metrics data), therefore the potential impact related to this vulnerability is minimal. The CVE-2023-0296 has been assigned to this issue to track the permanent fix in the etcd component.
The Birthday attack against
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
CISA ICS
Mitsubishi Electric Air Conditioning Systems
cisa_ics·2022-06-20
Mitsubishi Electric Air Conditioning Systems
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric Air Conditioning Systems
Last RevisedJune 20, 2022
Alert CodeICSA-22-160-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely
- Vendor: Mitsubishi Electric
- Equipment: Air Conditioning Systems
- Vulnerabilities: Use of a Broken or Risky Cryptographic Algorithm, Exposure of Sensitive Information to an Unauthorized Actor, Channel Accessible by Non-Endpoint
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to disclose or tamper data in communication between the air conditioning system and
Oracle
Oracle Oracle Siebel CRM Risk Matrix: EAI, SWSE (OpenSSL) — CVE-2016-2183
vendor_oracle·2021-10-15·CVSS 7.5
CVE-2016-2183 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: EAI, SWSE (OpenSSL) — CVE-2016-2183
Oracle Oracle Siebel CRM Risk Matrix: EAI, SWSE (OpenSSL) vulnerability
CVE: CVE-2016-2183
CVSS: 7.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
CISA ICS
GE UR family
cisa_ics·2021-03-16
GE UR family
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
GE UR family
Last RevisedMarch 16, 2021
Alert CodeICSA-21-075-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: GE
- Equipment: UR Family
- Vulnerabilities: Inadequate Encryption Strength, Session Fixation, Exposure of Sensitive Information to an Unauthorized Actor, Improper Input Validation, Unrestricted Upload of File with Dangerous Type, Insecure Default Variable Initialization, Use of Hard-coded Credentials
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to acce
Ubuntu
NSS vulnerability
vendor_ubuntu·2017-07-31·CVSS 7.5
CVE-2017-7502 [HIGH] NSS vulnerability
Title: NSS vulnerability
Summary: Several security issues were fixed in NSS.
It was discovered that NSS incorrectly handled certain empty SSLv2
messages. A remote attacker could possibly use this issue to cause NSS to
crash, resulting in a denial of service. (CVE-2017-7502)
Karthik Bhargavan and Gaetan Leurent discovered that the DES and Triple DES
ciphers were vulnerable to birthday attacks. A remote attacker could
possibly use this flaw to obtain clear text data from long encrypted
sessions. This update causes NSS to limit use of the same symmetric key.
(CVE-2016-2183)
It was discovered that NSS incorrectly handled Base64 decoding. A remote
attacker could use this flaw to cause NSS to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2017-5461)
Instru
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2017-04-27·CVSS 7.5
CVE-2016-2183 [HIGH] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
Karthik Bhargavan and Gaetan Leurent discovered that the DES and Triple DES
ciphers were vulnerable to birthday attacks. A remote attacker could
possibly use this flaw to obtain clear text data from long encrypted
sessions. This update causes NSS to limit use of the same symmetric key.
(CVE-2016-2183)
It was discovered that NSS incorrectly handled Base64 decoding. A remote
attacker could use this flaw to cause NSS to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2017-5461)
This update refreshes the NSS package to version 3.28.4 which includes
the latest CA certificate bundle.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2017-02-16·CVSS 7.5
CVE-2016-2183 [HIGH] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Karthik Bhargavan and Gaetan Leurent discovered that the DES and
Triple DES ciphers were vulnerable to birthday attacks. A remote
attacker could possibly use this flaw to obtain clear text data from
long encrypted sessions. This update moves those algorithms to the
legacy algorithm set and causes them to be used only if no non-legacy
algorithms can be negotiated. (CVE-2016-2183)
It was discovered that OpenJDK accepted ECSDA signatures using
non-canonical DER encoding. An attacker could use this to modify or
expose sensitive data. (CVE-2016-5546)
It was discovered that covert timing channel vulnerabilities existed
in the DSA implementations in OpenJDK. A remote attacker could use
this to expose se
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2017-02-09·CVSS 7.5
CVE-2016-2183 [HIGH] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Karthik Bhargavan and Gaetan Leurent discovered that the DES and
Triple DES ciphers were vulnerable to birthday attacks. A remote
attacker could possibly use this flaw to obtain clear text data from
long encrypted sessions. This update moves those algorithms to the
legacy algorithm set and causes them to be used only if no non-legacy
algorithms can be negotiated. (CVE-2016-2183)
It was discovered that OpenJDK accepted ECSDA signatures using
non-canonical DER encoding. An attacker could use this to modify or
expose sensitive data. (CVE-2016-5546)
It was discovered that OpenJDK did not properly verify object
identifier (OID) length when reading Distinguished Encoding Rules
(DER) records, as used in
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2017-01-25·CVSS 7.5
CVE-2016-2183 [HIGH] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
Karthik Bhargavan and Gaetan Leurent discovered that the DES and
Triple DES ciphers were vulnerable to birthday attacks. A remote
attacker could possibly use this flaw to obtain clear text data from
long encrypted sessions. This update moves those algorithms to the
legacy algorithm set and causes them to be used only if no non-legacy
algorithms can be negotiated. (CVE-2016-2183)
It was discovered that OpenJDK accepted ECSDA signatures using
non-canonical DER encoding. An attacker could use this to modify or
expose sensitive data. (CVE-2016-5546)
It was discovered that OpenJDK did not properly verify object
identifier (OID) length when reading Distinguished Encoding Rules
(DER) records, as used in
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco·2016-09-27·CVSS 5.5
CVE-2016-2177 [MEDIUM] CWE-119 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.”
Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.”
Of the 16 released vulnerabilities:
Fourteen track issues that could resu
Ubuntu
OpenSSL regression
vendor_ubuntu·2016-09-23·CVSS 9.8
CVE-2016-2182 [CRITICAL] OpenSSL regression
Title: OpenSSL regression
Summary: USN-3087-1 introduced a regression in OpenSSL.
USN-3087-1 fixed vulnerabilities in OpenSSL. The fix for CVE-2016-2182 was
incomplete and caused a regression when parsing certificates. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Shi Lei discovered that OpenSSL incorrectly handled the OCSP Status Request
extension. A remote attacker could possibly use this issue to cause memory
consumption, resulting in a denial of service. (CVE-2016-6304)
Guido Vranken discovered that OpenSSL used undefined behaviour when
performing pointer arithmetic. A remote attacker could possibly use this
issue to cause OpenSSL to crash, resulting in a denial of service. This
issue has only been addressed in Ubuntu 16.04 LTS in t
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2016-09-22·CVSS 9.8
CVE-2016-2177 [CRITICAL] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Shi Lei discovered that OpenSSL incorrectly handled the OCSP Status Request
extension. A remote attacker could possibly use this issue to cause memory
consumption, resulting in a denial of service. (CVE-2016-6304)
Guido Vranken discovered that OpenSSL used undefined behaviour when
performing pointer arithmetic. A remote attacker could possibly use this
issue to cause OpenSSL to crash, resulting in a denial of service. This
issue has only been addressed in Ubuntu 16.04 LTS in this update.
(CVE-2016-2177)
César Pereida, Billy Brumley, and Yuval Yarom discovered that OpenSSL
did not properly use constant-time operations when performing DSA signing.
A remote attacker could possibly use this issue to perf
Red Hat
SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32)
vendor_redhat·2016-08-24·CVSS 7.5
CVE-2016-2183 [HIGH] CWE-327 SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32)
SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32)
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
A flaw was found in the way the DES/3DES cipher was used as part of the TLS/SSL protocol. A man-in-the-middle attacker could use this flaw to recover some plaintext data by capturing large amounts of encrypted traffic between TLS/SSL server and client if the communication used a DES/3DES based ciphersuite.
Statement: OpenSSL security upd
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-2182 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-2182: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-6304 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-6304: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-6307 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-6307: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-6302 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-6302: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-6305 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-6305: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-6303 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-6303: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-2179 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-2179: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-6309 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-6309: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-2180 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-2180: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-2183 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-2183: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-6308 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-6308: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-2177 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-2177: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-6306 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-6306: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-7052 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-7052: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-2178 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-2178: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
vendor_cisco
CVE-2016-2181 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
CVE-2016-2181: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016
On September 22, 2016, the OpenSSL Software Foundation released an advisory that describes 14 vulnerabilities. Of these 14 vulnerabilities, the OpenSSL Software Foundation classifies one as “Critical Severity,” one as “Moderate Severity,” and the other 12 as “Low Severity.” Subsequently, on September 26, the OpenSSL Software Foundation released an additional advisory that describes two new vulnerabilities. These vulnerabilities affect the OpenSSL versions that were released to address the vulnerabilities disclosed in the previous advisory. One of the new vulnerabilities was rated as “High Severity” and the other as “Moderate Severity.” Of the 16 released vulnerabilities: Fourteen track issues that c
VulDB
Oracle HTTP Server up to 12.2.1.2.0 OSSL information disclosure (EDB-42091 / Nessus ID 103190)
vuldb·2026-05-30·CVSS 7.5
CVE-2016-2183 [HIGH] Oracle HTTP Server up to 12.2.1.2.0 OSSL information disclosure (EDB-42091 / Nessus ID 103190)
A vulnerability was found in Oracle HTTP Server 11.1.1.7.0/11.1.1.9.0/12.1.3.0.0/12.2.1.1.0/12.2.1.2.0. It has been classified as problematic. This affects an unknown part of the component OSSL Module. Performing a manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2016-2183. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Upgrading the affected component is recommended.
VulDB
Oracle Siebel UI Framework up to 21.9 OpenSSL information disclosure (ID 370412 / BID-92630)
vuldb·2026-05-30·CVSS 7.5
CVE-2016-2183 [HIGH] Oracle Siebel UI Framework up to 21.9 OpenSSL information disclosure (ID 370412 / BID-92630)
A vulnerability was found in Oracle Siebel UI Framework up to 21.9. It has been declared as critical. Affected is an unknown function of the component OpenSSL. Such manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2016-2183. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
VulDB
Oracle Database Server 11.2.0.4/12.1.0.2 Real Application Clusters information disclosure (EDB-42091 / Nessus ID 95255)
vuldb·2026-05-30·CVSS 7.5
CVE-2016-2183 [HIGH] Oracle Database Server 11.2.0.4/12.1.0.2 Real Application Clusters information disclosure (EDB-42091 / Nessus ID 95255)
A vulnerability classified as critical was found in Oracle Database Server 11.2.0.4/12.1.0.2. This affects an unknown function of the component Real Application Clusters. The manipulation results in information disclosure.
This vulnerability is reported as CVE-2016-2183. The attack can be launched remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
VulDB
OpenSSL 1.0.1/1.0.2/1.1.0 64-bit Block Cipher SWEET32 information disclosure (SWEET32 / EDB-42091)
vuldb·2026-05-29·CVSS 7.5
CVE-2016-2183 [HIGH] OpenSSL 1.0.1/1.0.2/1.1.0 64-bit Block Cipher SWEET32 information disclosure (SWEET32 / EDB-42091)
A vulnerability categorized as critical has been discovered in OpenSSL 1.0.1/1.0.2/1.1.0. Affected by this issue is some unknown functionality of the component 64-bit Block Cipher. Such manipulation leads to information disclosure (SWEET32).
This vulnerability is listed as CVE-2016-2183. The attack may be performed from remote. In addition, an exploit is available.
VulDB
Oracle Java SE 6u131/7u121/8u112 Libraries information disclosure (EDB-42091 / Nessus ID 92542)
vuldb·2026-05-29·CVSS 7.5
CVE-2016-2183 [HIGH] Oracle Java SE 6u131/7u121/8u112 Libraries information disclosure (EDB-42091 / Nessus ID 92542)
A vulnerability was found in Oracle Java SE 6u131/7u121/8u112 and classified as problematic. Impacted is an unknown function of the component Libraries. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2016-2183. The attack may be launched remotely. Furthermore, there is an exploit available.
It is suggested to upgrade the affected component.
VulDB
OpenSSL 1.0.1/1.0.2 DES/3DES SWEET32 missing encryption (EDB-42091 / ID 370412)
vuldb·2026-05-29·CVSS 7.5
CVE-2016-2183 [HIGH] OpenSSL 1.0.1/1.0.2 DES/3DES SWEET32 missing encryption (EDB-42091 / ID 370412)
A vulnerability, which was classified as problematic, was found in OpenSSL 1.0.1/1.0.2. This issue affects some unknown processing of the component DES/3DES. Such manipulation leads to missing encryption of sensitive data (SWEET32).
This vulnerability is listed as CVE-2016-2183. The attack may be performed from remote. In addition, an exploit is available.
You should upgrade the affected component.
OSV
Kyverno vulnerable due to usage of insecure cipher
osv·2023-05-30·CVSS 7.5
CVE-2016-2183 [HIGH] Kyverno vulnerable due to usage of insecure cipher
Kyverno vulnerable due to usage of insecure cipher
### Summary
Insecure 3DES ciphers are used which may lead to exploitation of the [Sweet32 vulnerability](https://sweet32.info/). Specifically, the ciphers TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA (secp256r1) and TLS_RSA_WITH_3DES_EDE_CBC_SHA (rsa 2048) are allowed. See CVE-2016-2183. This is fixed in Kyverno v1.9.5 and v1.10.0 and no known users have been affected.
### Details
The ciphers in affected versions can be read using the following command which uses `nmap`:
```sh
$ kubectl exec -it mypod -n kyverno sh
kubectl exec [POD] [COMMAND] is DEPRECATED and will be removed in a future version. Use kubectl exec [POD] -- [COMMAND] instead.
**nmap -sV --script ssl-enum-ciphers -p 443 kyverno-cleanup-controller** or
**nmap -sV --script ssl-enum
GHSA
Kyverno vulnerable due to usage of insecure cipher
ghsa·2023-05-30·CVSS 7.5
CVE-2016-2183 [HIGH] Kyverno vulnerable due to usage of insecure cipher
Kyverno vulnerable due to usage of insecure cipher
### Summary
Insecure 3DES ciphers are used which may lead to exploitation of the [Sweet32 vulnerability](https://sweet32.info/). Specifically, the ciphers TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA (secp256r1) and TLS_RSA_WITH_3DES_EDE_CBC_SHA (rsa 2048) are allowed. See CVE-2016-2183. This is fixed in Kyverno v1.9.5 and v1.10.0 and no known users have been affected.
### Details
The ciphers in affected versions can be read using the following command which uses `nmap`:
```sh
$ kubectl exec -it mypod -n kyverno sh
kubectl exec [POD] [COMMAND] is DEPRECATED and will be removed in a future version. Use kubectl exec [POD] -- [COMMAND] instead.
**nmap -sV --script ssl-enum-ciphers -p 443 kyverno-cleanup-controller** or
**nmap -sV --script ssl-enum
GHSA
GHSA-wpff-vmpr-5q22: The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component
ghsa_unreviewed·2023-01-17·CVSS 7.5
CVE-2023-0296 [HIGH] CWE-327 GHSA-wpff-vmpr-5q22: The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary to open up a new port (9979) on etcd grpc-proxy, hence this port might be considered as still vulnerable to the same type of vulnerability. The health checks on etcd grpc-proxy do not contain sensitive data (only metrics data), therefore the potential impact related to this vulnerability is minimal. The CVE-2023-0296 has been assigned to this issue to track the permanent fix in the etcd component.
GHSA
GHSA-w2rw-pv8p-h9c8: The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately
ghsa_unreviewed·2022-05-13
CVE-2016-2183 [HIGH] CWE-200 GHSA-w2rw-pv8p-h9c8: The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
OSV
nss vulnerabilities
osv·2017-04-27·CVSS 7.5
CVE-2016-2183 [HIGH] nss vulnerabilities
nss vulnerabilities
Karthik Bhargavan and Gaetan Leurent discovered that the DES and Triple DES
ciphers were vulnerable to birthday attacks. A remote attacker could
possibly use this flaw to obtain clear text data from long encrypted
sessions. This update causes NSS to limit use of the same symmetric key.
(CVE-2016-2183)
It was discovered that NSS incorrectly handled Base64 decoding. A remote
attacker could use this flaw to cause NSS to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2017-5461)
This update refreshes the NSS package to version 3.28.4 which includes
the latest CA certificate bundle.
OSV
openjdk-7 vulnerabilities
osv·2017-02-09·CVSS 7.5
CVE-2016-2183 [HIGH] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Karthik Bhargavan and Gaetan Leurent discovered that the DES and
Triple DES ciphers were vulnerable to birthday attacks. A remote
attacker could possibly use this flaw to obtain clear text data from
long encrypted sessions. This update moves those algorithms to the
legacy algorithm set and causes them to be used only if no non-legacy
algorithms can be negotiated. (CVE-2016-2183)
It was discovered that OpenJDK accepted ECSDA signatures using
non-canonical DER encoding. An attacker could use this to modify or
expose sensitive data. (CVE-2016-5546)
It was discovered that OpenJDK did not properly verify object
identifier (OID) length when reading Distinguished Encoding Rules
(DER) records, as used in x.509 certificates and elsewhere. An
attacker could use this to c
OSV
openjdk-8 vulnerabilities
osv·2017-01-25·CVSS 7.5
CVE-2016-2183 [HIGH] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
Karthik Bhargavan and Gaetan Leurent discovered that the DES and
Triple DES ciphers were vulnerable to birthday attacks. A remote
attacker could possibly use this flaw to obtain clear text data from
long encrypted sessions. This update moves those algorithms to the
legacy algorithm set and causes them to be used only if no non-legacy
algorithms can be negotiated. (CVE-2016-2183)
It was discovered that OpenJDK accepted ECSDA signatures using
non-canonical DER encoding. An attacker could use this to modify or
expose sensitive data. (CVE-2016-5546)
It was discovered that OpenJDK did not properly verify object
identifier (OID) length when reading Distinguished Encoding Rules
(DER) records, as used in x.509 certificates and elsewhere. An
attacker could use this to c
OSV
openssl regression
osv·2016-09-23·CVSS 9.8
CVE-2016-2182 [CRITICAL] openssl regression
openssl regression
USN-3087-1 fixed vulnerabilities in OpenSSL. The fix for CVE-2016-2182 was
incomplete and caused a regression when parsing certificates. This update
fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Shi Lei discovered that OpenSSL incorrectly handled the OCSP Status Request
extension. A remote attacker could possibly use this issue to cause memory
consumption, resulting in a denial of service. (CVE-2016-6304)
Guido Vranken discovered that OpenSSL used undefined behaviour when
performing pointer arithmetic. A remote attacker could possibly use this
issue to cause OpenSSL to crash, resulting in a denial of service. This
issue has only been addressed in Ubuntu 16.04 LTS in this update.
(CVE-2016-2177)
César Pereida, Billy Brumley, and Y
OSV
openssl vulnerabilities
osv·2016-09-22·CVSS 9.8
CVE-2016-6304 [CRITICAL] openssl vulnerabilities
openssl vulnerabilities
Shi Lei discovered that OpenSSL incorrectly handled the OCSP Status Request
extension. A remote attacker could possibly use this issue to cause memory
consumption, resulting in a denial of service. (CVE-2016-6304)
Guido Vranken discovered that OpenSSL used undefined behaviour when
performing pointer arithmetic. A remote attacker could possibly use this
issue to cause OpenSSL to crash, resulting in a denial of service. This
issue has only been addressed in Ubuntu 16.04 LTS in this update.
(CVE-2016-2177)
César Pereida, Billy Brumley, and Yuval Yarom discovered that OpenSSL
did not properly use constant-time operations when performing DSA signing.
A remote attacker could possibly use this issue to perform a cache-timing
attack and recover private DSA keys. (CVE-201
OSV
CVE-2016-2183: The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately
osv·2016-09-01·CVSS 7.5
CVE-2016-2183 [HIGH] CVE-2016-2183: The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
No detection rules found.
HackerOne
blockstack.org - is vulnerable to (CVE-2016-2183, CVE-2016-6329)
hackerone·2025-10-31·CVSS 7.5
CVE-2016-2183 [HIGH] blockstack.org - is vulnerable to (CVE-2016-2183, CVE-2016-6329)
blockstack.org - is vulnerable to (CVE-2016-2183, CVE-2016-6329)
**Descriptions**
Cryptographic protocols like TLS, SSH, IPsec, and OpenVPN commonly use block cipher algorithms, such as AES, Triple-DES, and Blowfish, to encrypt data between clients and servers. To use such algorithms, the data is broken into fixed-length chunks, called blocks, and each block is encrypted separately according to a mode of operation. Older block ciphers, such as Triple-DES and Blowfish use a block size of 64 bits, whereas AES uses a block size of 128 bits.
A attacker can can decrypt victim data using Sweet32 birthday attck vulnerability over wifi or (local network)
Hackerone Refferals #232463 #375097 #216271 #210331
###Steps To Reproduce:
- open nmap and type: ``nmap --script ssl-enum-ciphers blockstack.or
HackerOne
Vulnerability Report - sweet32 UPchieve
hackerone·2021-07-28
[NONE] Vulnerability Report - sweet32 UPchieve
Vulnerability Report - sweet32 UPchieve
Hello Team.
I run the nmap with ssl-enum script to look for new Vulnerability that is known as "SWEET32"
Detail about sweet32 vuln:~
Cryptographic protocols like TLS, SSH, IPsec, and OpenVPN commonly use block cipher algorithms, such as AES, Triple-DES, and Blowfish, to encrypt data between clients and servers. To use such algorithms, the data is broken into fixed-length chunks, called blocks, and each block is encrypted separately according to a mode of operation. Older block ciphers, such as Triple-DES and Blowfish use a block size of 64 bits, whereas AES uses a block size of 128 bits.
note: this vulnerability and exploitation has been demo'ed at defcon
ref site: https://sweet32.info/
Here is another article on sweet32 https://bobcares.com/b
Bugzilla
CVE-2016-2183 openshift-enterprise-console-container: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [openshift-enterprise-3.11.z]
bugzilla·2019-08-26·CVSS 7.5
CVE-2016-2183 [HIGH] CVE-2016-2183 openshift-enterprise-console-container: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [openshift-enterprise-3.11.z]
CVE-2016-2183 openshift-enterprise-console-container: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [openshift-enterprise-3.11.z]
Reproduced on v3.11.141 for console image.
Discussion:
Yanping, any reason this should not also be fixed in 4.x console?
Opening https://github.com/openshift/console/pull/3389 to begin to address.
---
Jason, since we have branched for 4.3, can we get a 4.4 clone?
---
Created 1777129 for 4.4
---
Waiting on 4.5 fix to backport.
---
This bug did not complete in the current cycle. Adding UpcomingSprint to have it re-evaluated in the next sprint.
---
Will fix next sprint
---
In the middle of backport process.
---
Thank you for continuing to use Red Hat OpenShift. As part of a wider bug review, this bug has been evaluated and we hav
HackerOne
Yelp.com is vulnerable to SWEET32 attack
hackerone·2017-11-09·CVSS 7.5
CVE-2016-2183 [HIGH] Yelp.com is vulnerable to SWEET32 attack
Yelp.com is vulnerable to SWEET32 attack
Researchers have found new attack against 3DES-CBC cipher in TLS,that they can decrypt customer data using a method called SWEET32 Birthday Attack.
This Vulnerability has got CVE-2016-2183 and has cvss score 5.0
This vulnerability can be found manually by simply using nmap script
nmap -Pn -p --script ssl-enum-ciphers ip
Mitigation for SWEET32 attack
->Prefer minimum 128-bit cipher suites
->Limit the length of TLS sessions with a 64-bit cipher, which could be done with TLS renegotiation or closing and starting a new connection
-> Disable cipher suites using 3DES
Reference link: https://sweet32.info/
HackerOne
sweet32
hackerone·2017-05-04·CVSS 7.5
CVE-2016-2183 [HIGH] sweet32
sweet32
hello
have found new attack against 3DES-CBC cipher in TLS,that they can decrypt customer data using a method called SWEET32 Birthday Attack.
This Vulnerability has got CVE-2016-2183 and has cvss score 5.0
in atach you will see a print screen vuln confirmation by nmap script
Mitigation for SWEET32 attack
Prefer minimum 128-bit cipher suites
Limit the length of TLS sessions with a 64-bit cipher, which could be done with TLS renegotiation or closing and starting a new connection
Disable cipher suites using 3DES
HackerOne
SSL/TLS Vulnerability at khanacademy.org
hackerone·2017-02-22·CVSS 7.5
[HIGH] SSL/TLS Vulnerability at khanacademy.org
SSL/TLS Vulnerability at khanacademy.org
CVE - 2011 - 3389
Description :
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.
Problem Location :
https://www.khanacademy.org/
Mitigation :
The Upgrade TLS version on the server to latest stable version
CVE - 2013 - 0169 :
Description :
The TLS protocol 1.1
HackerOne
SWEET32 TLS attack
hackerone·2017-02-01·CVSS 7.5
CVE-2016-2183 [HIGH] SWEET32 TLS attack
SWEET32 TLS attack
Researchers have found new attack against 3DES-CBC cipher in TLS,that they can decrypt customer data using a method called SWEET32 Birthday Attack.
This Vulnerability has got CVE-2016-2183 and has cvss score 5.0
This vulnerability can be found manually by simply using nmap script
nmap -Pn -p --script ssl-enum-ciphers ip
Mitigation for SWEET32 attack
->Prefer minimum 128-bit cipher suites
->Limit the length of TLS sessions with a 64-bit cipher, which could be done with TLS renegotiation or closing and starting a new connection
-> Disable cipher suites using 3DES
HackerOne
Nextcloud.com is vulnerable to SWEET32 attack
hackerone·2017-01-25·CVSS 7.5
CVE-2016-2183 [HIGH] Nextcloud.com is vulnerable to SWEET32 attack
Nextcloud.com is vulnerable to SWEET32 attack
Researchers have found new attack against 3DES-CBC cipher in TLS,that they can decrypt customer data using a method called SWEET32 Birthday Attack.
This Vulnerability has got CVE-2016-2183 and has cvss score 5.0
This vulnerability can be found manually by simply using nmap script
nmap -Pn -p --script ssl-enum-ciphers ip
Mitigation for SWEET32 attack
->Prefer minimum 128-bit cipher suites
->Limit the length of TLS sessions with a 64-bit cipher, which could be done with TLS renegotiation or closing and starting a new connection
-> Disable cipher suites using 3DES
Reference link: https://sweet32.info/
Bugzilla
CVE-2016-2183 openssl101e: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [epel-5]
bugzilla·2016-10-26·CVSS 7.5
CVE-2016-2183 [HIGH] CVE-2016-2183 openssl101e: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [epel-5]
CVE-2016-2183 openssl101e: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by
Bugzilla
CVE-2016-2183 nss: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [fedora-all]
bugzilla·2016-10-26·CVSS 7.5
CVE-2016-2183 [HIGH] CVE-2016-2183 nss: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [fedora-all]
CVE-2016-2183 nss: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2016-2183 mingw-openssl: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [fedora-all]
bugzilla·2016-10-26·CVSS 7.5
CVE-2016-2183 [HIGH] CVE-2016-2183 mingw-openssl: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [fedora-all]
CVE-2016-2183 mingw-openssl: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2016-2183 openssl: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [fedora-all]
bugzilla·2016-10-26·CVSS 7.5
CVE-2016-2183 [HIGH] CVE-2016-2183 openssl: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [fedora-all]
CVE-2016-2183 openssl: SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2016-2183 SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32)
bugzilla·2016-08-23·CVSS 7.5
CVE-2016-2183 [HIGH] CVE-2016-2183 SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32)
CVE-2016-2183 SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32)
Ciphers with 64-bit block sizes used in CBC mode were found to be vulnerable to birthday attack when key renegotiation doesn't happen frequently or at all in long running connections. 3DES cipher as used in TLS protocol is vulnerable to this attack, that allows remote attacker to recover partial plaintext information (XOR of two plaintext blocks).
Discussion:
Acknowledgments:
Name: OpenVPN
Upstream: Karthikeyan Bhargavan (Inria), Gaëtan Leurent (Inria)
---
Upstream Security fixes:
1.OpenSSL has moved 3DES ciphersuites from the HIGH category to MEDIUM in the 1.0.2 branch, and will disable it by default in the upcoming 1.1.0 release.
2. Mozilla NSS is implementing data limits for all ciphersuites:
https://b
arXiv
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
arxiv_fulltext·2024-07-31
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Raveen Kanishka Jayalath*
University of Adelaide, Australia
[email protected]
Hussain Ahmad* *Authors contributed equally to this work. Corresponding author.
University of Adelaide, Australia
[email protected]
Diksha Goel
CSIRO's Data61, Australia
[email protected]
3cmMuhammad Shuja Syed
3cmSLB, USA
[email protected]
Faheem Ullah
University of Adelaide, Australia
[email protected]
plain
## Abstract
Microservice architectures are revolutionizing both small businesses and large corporations, igniting a new era of innovation with their exceptional advantages in maintainability, reusability, and scalability. However, these benefits come w
arXiv
Secure by default - the case of TLS
arxiv_fulltext·2017-08-24
Secure by default - the case of TLS
Secure by default -- the case of TLS
Martin Stanek \ 1ex]
Department of Computer Science
Comenius University
@dcs.fmph.uniba.sk
## Abstract
Default configuration of various software applications often neglects security objectives.
We tested the default configuration of TLS in dozen web and application servers.
The results show that ``secure by default'' principle should be adopted more broadly
by developers and package maintainers. In addition, system administrators cannot
rely blindly on default security options.
: TLS, secure defaults, testing.
## Introduction
Security often depends on prudent configuration of software components used in a deployed
system. All necessary security controls and options are there, but one have
to turn them on or simply start using them. Unfortunately
Hackernews
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
blogs_hackernews·2026-07-10
CVE-2016-6329 Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure.
The apps flagged with at least one problem have been installed more than 2.4 billion times.
The problems are basic, not sophisticated. 29 apps let user traffic leak outside the encrypted tunnel, including the DNS lookups that reveal which websites you visit. 61 apps send some data in plain text that anyone watching the tr
Tenable
[R1] LCE 5.0.1 Fixes Two Third-party Library Vulnerabilities
blogs_tenable·2017-03-22
[R1] LCE 5.0.1 Fixes Two Third-party Library Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Huntress
CVE-2016-2183 Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 7.5
CVE-2016-2183 [HIGH] CVE-2016-2183 Vulnerability: Analysis, Impact, Mitigation | Huntress
## CVE-2016-2183 Vulnerability
Published: 12/05/2025
Written by: Lizzie Danielson
## What is CVE-2016-2183 vulnerability?
CVE-2016-2183, also known as the "SWEET32" vulnerability, is a security flaw in block cipher algorithms using 64-bit block sizes within obsolete versions of TLS (Transport Layer Security) and SSL (Secure Sockets Layer). This vulnerability, classified as a cryptographic weakness, enables attackers to exploit birthday attacks against encrypted data, potentially compromising sensitive communications. The issue mainly arises from the use of outdated encryption algorithms such as Triple DES (3DES), which, despite being phased out, still exist in legacy systems.
## When was it discovered?
CVE-2016-2183 first came to light in August 2016 when researchers Mathy Vanhoef an
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-01/msg00068.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-02/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-02/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-02/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-05/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.htmlhttp://packetstormsecurity.com/files/142756/IBM-Informix-Dynamic-Server-DLL-Injection-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0336.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0337.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0338.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0462.htmlhttp://seclists.org/fulldisclosure/2017/Jul/31http://seclists.org/fulldisclosure/2017/May/105http://seclists.org/fulldisclosure/2017/May/105http://seclists.org/fulldisclosure/2017/May/105http://seclists.org/fulldisclosure/2017/May/105http://www-01.ibm.com/support/docview.wss?uid=nas8N1021697http://www-01.ibm.com/support/docview.wss?uid=swg21991482http://www-01.ibm.com/support/docview.wss?uid=swg21995039http://www.debian.org/security/2016/dsa-3673http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170322-01-openssl-enhttp://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.securityfocus.com/archive/1/539885/100/0/threadedhttp://www.securityfocus.com/archive/1/540341/100/0/threadedhttp://www.securityfocus.com/archive/1/541104/100/0/threadedhttp://www.securityfocus.com/archive/1/542005/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/539885/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540129/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540341/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/541104/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/542005/100/0/threadedhttp://www.securityfocus.com/bid/92630http://www.securityfocus.com/bid/95568http://www.securitytracker.com/id/1036696http://www.splunk.com/view/SP-CAAAPSVhttp://www.splunk.com/view/SP-CAAAPUEhttp://www.ubuntu.com/usn/USN-3087-1http://www.ubuntu.com/usn/USN-3087-2http://www.ubuntu.com/usn/USN-3179-1http://www.ubuntu.com/usn/USN-3194-1http://www.ubuntu.com/usn/USN-3198-1http://www.ubuntu.com/usn/USN-3270-1http://www.ubuntu.com/usn/USN-3372-1https://access.redhat.com/articles/2548661https://access.redhat.com/errata/RHSA-2017:1216https://access.redhat.com/errata/RHSA-2017:2708https://access.redhat.com/errata/RHSA-2017:2709https://access.redhat.com/errata/RHSA-2017:2710https://access.redhat.com/errata/RHSA-2017:3113https://access.redhat.com/errata/RHSA-2017:3114https://access.redhat.com/errata/RHSA-2017:3239https://access.redhat.com/errata/RHSA-2017:3240https://access.redhat.com/errata/RHSA-2018:2123https://access.redhat.com/errata/RHSA-2019:1245https://access.redhat.com/errata/RHSA-2019:2859https://access.redhat.com/errata/RHSA-2020:0451https://access.redhat.com/security/cve/cve-2016-2183https://blog.cryptographyengineering.com/2016/08/24/attack-of-week-64-bit-ciphers-in-tls/https://bto.bluecoat.com/security-advisory/sa133https://bugzilla.redhat.com/show_bug.cgi?id=1369383https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://github.com/ssllabs/ssllabs-scan/issues/387#issuecomment-242514633https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05302448https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05369403https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05369415https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05385680https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05390722https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05390849https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03765en_ushttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03725en_ushttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05302448https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05309984https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05323116https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05349499https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05356388https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369403https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369415https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05385680https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390849
+ 178 more references
2016-09-01
Published