PT-2016-3301 · Openvpn+5 · Openvpn+5
Gaãtan Leurent
+1
·
Published
2016-08-24
·
Updated
2025-10-21
·
CVE-2016-6329
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenVPN versions prior to the fixed version
Description
The issue is related to the use of 64-bit block ciphers in OpenVPN, which can be exploited by remote attackers to obtain cleartext data via a birthday attack, specifically a "Sweet32" attack, against long-duration encrypted sessions. This can be demonstrated in an HTTP-over-OpenVPN session using Blowfish in CBC mode.
Recommendations
For OpenVPN versions prior to the fixed version, consider disabling the use of 64-bit block ciphers, such as Blowfish in CBC mode, until a patch is available. Restrict access to sensitive data transmitted over OpenVPN to minimize the risk of exploitation. As a temporary workaround, consider using alternative encryption methods that are not affected by the "Sweet32" attack.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Nessus
Openvpn
Suse
Ubuntu