CVE-2016-2183
high · 7.5The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
7.5
CVSS
95.7%
EPSS (exploit prob.)
100th
EPSS percentile
2016-09-01
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| redhat | jboss_enterprise_application_platform | 6.0.0 |
| redhat | jboss_enterprise_web_server | 1.0.0 |
| redhat | jboss_enterprise_web_server | 2.0.0 |
| redhat | jboss_web_server | 3.0 |
| redhat | enterprise_linux | 5.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| python | python | >= 2.7.0, < 2.7.13 |
| python | python | >= 3.4.0, < 3.4.7 |
| python | python | >= 3.5.0, < 3.5.3 |
| cisco | content_security_management_appliance | 9.6.6-068 |
| cisco | content_security_management_appliance | 9.7.0-006 |
| openssl | openssl | 1.0.1a |
| openssl | openssl | 1.0.1b |
| openssl | openssl | 1.0.1c |
| openssl | openssl | 1.0.1d |
| openssl | openssl | 1.0.1e |
| openssl | openssl | 1.0.1f |
| openssl | openssl | 1.0.1g |
| openssl | openssl | 1.0.1h |
| openssl | openssl | 1.0.1i |
| openssl | openssl | 1.0.1j |
| openssl | openssl | 1.0.1k |
| openssl | openssl | 1.0.1l |
| openssl | openssl | 1.0.1m |
| openssl | openssl | 1.0.1n |
| openssl | openssl | 1.0.1o |
| openssl | openssl | 1.0.1p |
| openssl | openssl | 1.0.1q |
| openssl | openssl | 1.0.1r |
| openssl | openssl | 1.0.1t |
| openssl | openssl | 1.0.2a |
| openssl | openssl | 1.0.2b |
| openssl | openssl | 1.0.2c |
| openssl | openssl | 1.0.2d |
| openssl | openssl | 1.0.2e |
| openssl | openssl | 1.0.2f |
| openssl | openssl | 1.0.2h |
| oracle | database | 11.2.0.4 |
| oracle | database | 12.1.0.2 |
Check a specific version with /api/v1/cve/match.
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2017-01/msg00068.html
- http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00028.html
- http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2017-05/msg00076.html
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html
- http://packetstormsecurity.com/files/142756/IBM-Informix-Dynamic-Server-DLL-Injection-Code-Execution.html
- http://rhn.redhat.com/errata/RHSA-2017-0336.html
- http://rhn.redhat.com/errata/RHSA-2017-0337.html
- http://rhn.redhat.com/errata/RHSA-2017-0338.html
- http://rhn.redhat.com/errata/RHSA-2017-0462.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-2183