PT-2016-3343 · Ipsec+15 · Ipsec+20

Published

2016-08-31

·

Updated

2026-03-10

·

CVE-2016-2183

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified) TLS, SSH, and IPSec protocols (affected versions not specified) Integrated Lights-Out 4 (iLO 4) (affected versions not specified)
Description The DES and Triple DES ciphers have a birthday bound of approximately four billion blocks, making it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session. This issue is also known as a "Sweet32" attack. To exploit this vulnerability, both the OpenSSL server and client have to use 3DES to encrypt data over SSL, and only after 32GB have been transferred can the attacker begin to decrypt data.
Recommendations For OpenSSL, consider disabling the use of 3DES cipher to encrypt data over SSL until a patch is available. For TLS, SSH, and IPSec protocols, restrict the use of DES and Triple DES ciphers to minimize the risk of exploitation. For Integrated Lights-Out 4 (iLO 4), consider applying security updates or patches to address the potential impact of the SWEET32 attack. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2005
ALT-PU-2016-2068
ALT-PU-2017-2598
ALT-PU-2017-2851
BDU:2017-01833
BDU:2021-03140
CESA-2016_1940
CESA-2018_2123
CVE-2016-2183
DSA-3673-1
MGASA-2016-0338
MGASA-2016-0408
MGASA-2017-0041
OPENSUSE-SU-2016_2391-1
OPENSUSE-SU-2016_2407-1
OPENSUSE-SU-2016_2496-1
OPENSUSE-SU-2016_2537-1
OPENSUSE-SU-2017_0374-1
OPENSUSE-SU-2017_0513-1
OPENSUSE-SU-2018_0458-1
OPENSUSE-SU-2024:10247-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10876-1
OPENSUSE-SU-2024:11127-1
OPENSUSE-SU-2024:11130-1
PSF-2016-4
RHSA-2016:1940
RHSA-2016_1940
RHSA-2017:0336
RHSA-2017:0337
RHSA-2017:0338
RHSA-2017:0462
RHSA-2017:1216
RHSA-2017:2709
RHSA-2017:2710
RHSA-2017:3113
RHSA-2017:3240
RHSA-2017_0336
RHSA-2017_0338
RHSA-2017_0462
RHSA-2018:2123
RHSA-2018_2123
SUSE-FU-2022:0445-1
SUSE-SU-2016:2387-1
SUSE-SU-2016:2394-1
SUSE-SU-2016:2458-1
SUSE-SU-2016:2468-1
SUSE-SU-2016:2469-1
SUSE-SU-2016:2470-1
SUSE-SU-2016:2470-2
SUSE-SU-2016:2545-1
SUSE-SU-2017:0346-1
SUSE-SU-2017:0460-1
SUSE-SU-2017:0490-1
SUSE-SU-2017:0716-1
SUSE-SU-2017:0719-1
SUSE-SU-2017:0720-1
SUSE-SU-2017:0726-1
SUSE-SU-2017:0839-1
SUSE-SU-2017:1389-1
SUSE-SU-2017:1444-1
SUSE-SU-2017:2699-1
SUSE-SU-2017:2700-1
SUSE-SU-2017_0346-1
SUSE-SU-2017_0460-1
SUSE-SU-2017_0490-1
SUSE-SU-2017_0716-1
SUSE-SU-2017_0719-1
SUSE-SU-2017_0720-1
SUSE-SU-2017_0726-1
SUSE-SU-2017_0839-1
SUSE-SU-2017_1389-1
SUSE-SU-2017_1444-1
SUSE-SU-2019:14246-1
SUSE-SU-2019_14246-1
USN-3087-1
USN-3087-2
USN-3179-1
USN-3194-1
USN-3198-1
USN-3270-1
USN-3372-1

Affected Products

Alt Linux
Centos
Cisco Asa
Cisco Ios Xe
Cisco Ios Xr
Cisco Nexus
Cisco Wls
Fortios
Hpe Ilo
Huawei Vrp
Ibm Aix
Ipsec
Java Platform
Junos
Openssl
Red Hat
Ssh
Suse
Tls
Ubuntu
Ilo 4