PT-2016-3301 · Openvpn+5 · Openvpn+5

Gaãtan Leurent

+1

·

Published

2016-08-24

·

Updated

2025-10-21

·

CVE-2016-6329

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenVPN versions prior to the fixed version
Description The issue is related to the use of 64-bit block ciphers in OpenVPN, which can be exploited by remote attackers to obtain cleartext data via a birthday attack, specifically a "Sweet32" attack, against long-duration encrypted sessions. This can be demonstrated in an HTTP-over-OpenVPN session using Blowfish in CBC mode.
Recommendations For OpenVPN versions prior to the fixed version, consider disabling the use of 64-bit block ciphers, such as Blowfish in CBC mode, until a patch is available. Restrict access to sensitive data transmitted over OpenVPN to minimize the risk of exploitation. As a temporary workaround, consider using alternative encryption methods that are not affected by the "Sweet32" attack.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1187
BDU:2019-04216
CVE-2016-6329
MGASA-2016-0304
SUSE-SU-2017:1622-1
SUSE-SU-2017:2838-1
SUSE-SU-2017_1622-1
SUSE-SU-2017_2838-1
USN-3339-1

Affected Products

Alt Linux
Debian
Nessus
Openvpn
Suse
Ubuntu