CVE-2016-2183

Modified
Published: 01 Sept 2016, 00:00
Last modified:29 May 2026, 20:25

Vulnerability Summary

Overall Risk (default)
medium
48/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
40.99% HIGH
41% probability +0.39%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

01 Sept 2016, 00:00
Published
Vulnerability first disclosed
29 May 2026, 20:25
Last Modified
Vulnerability information updated

Description

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 40.99% Percentile: 97%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • ciscocontent_security_management_appliance

    9.6.6-068 | 9.7.0-006

  • nodejsnode.js

    ≥ 0.10.0, < 0.10.47 | ≥ 0.12.0, < 0.12.16 | ≥ 4.0.0, < 4.1.2 | ≥ 4.2.0, < 4.6.0 | ≥ 6.0.0, < 6.7.0

  • UnknownOpenSSL

    1.0.1a | 1.0.1b | 1.0.1c | 1.0.1d | 1.0.1e | 1.0.1f | 1.0.1g | 1.0.1h | 1.0.1i | 1.0.1j | 1.0.1k | 1.0.1l | 1.0.1m | 1.0.1n | 1.0.1o | 1.0.1p | 1.0.1q | 1.0.1r | 1.0.1t | 1.0.2a | 1.0.2b | 1.0.2c | 1.0.2d | 1.0.2e | 1.0.2f | 1.0.2h

  • oracledatabase

    11.2.0.4 | 12.1.0.2

  • pythonpython

    ≥ 2.7.0, < 2.7.13 | ≥ 3.4.0, < 3.4.7 | ≥ 3.5.0, < 3.5.3

  • redhatenterprise_linux

    5.0 | 6.0 | 7.0

  • redhatjboss_enterprise_application_platform

    6.0.0

  • redhatjboss_enterprise_web_server

    1.0.0 | 2.0.0

  • redhatjboss_web_server

    3.0

References (137)