CVE-2016-2183
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
- Affected products
- Alt Linux, Centos, Cisco Asa, Cisco Ios Xe, Cisco Ios Xr, Cisco Nexus, Cisco Wls, Fortios
- Redhat Jboss Enterprise Application Platform
- = 6.0.0
- Redhat Jboss Enterprise Web Server
- = 1.0.0, 2.0.0
- Redhat Jboss Web Server
- = 3.0
- Redhat Enterprise Linux
- = 5.0, 6.0, 7.0
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 95.7% (100th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2016-09-01
CVE-2016-2183 at NVD
9 known exploits for CVE-2016-2183
Proof-of-concept code and exploit modules indexed by Sploitus
Simple-Sweet32
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Redhat Jboss_Enterprise_Application_Platform
Orion Elite Hidden IP Browser Pro 7.9 OpenSSL / Tor / Man-In-The-Middle
IBM Informix Dynamic Server DLL Injection / Code Execution
IBM Informix Dynamic Server / Informix Open Admin Tool - DLL Injection / Remote Code Execution / Hea
IBM Informix Dynamic Server Informix Open Admin Tool - DLL Injection Remote Code Execution Heap Buffer Overflow
IBM Informix Dynamic Server / Informix Open Admin Tool - DLL Injection / Remote Code Execution / Heap Buffer Overflow
IBM Informix Dynamic Server Open Admin Tool RCE (CVE-2017-1092)
arch-audit - An utility like pkg-audit for Arch Linux