← Vulnerability feed

Vulnerability record · CVE-2016-2183 · published 1 September 2016

CVE-2016-2183: DES/3DES Birthday Bound Flaw Enables Cleartext Recovery (Sweet32)

Redhat · Jboss Enterprise Application Platform

DES and Triple DES ciphers used in TLS, SSH, IPSec and other protocols have a birthday bound of roughly four billion blocks, allowing a birthday attack against long-duration encrypted sessions. An attacker who can capture enough ciphertext from a single long-lived session can recover cleartext data, as demonstrated against HTTPS using Triple DES in CBC mode (Sweet32).

7.5 CVSS 3.1 High EPSS 95% · top 0.1% CWE-200 · Information exposure
7.5CVSS 3.1 base score, v2 5.0
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
286References
17 Jun 2026Last modified by NVD

Description

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 7.5 with network reachability and high confidentiality impact, plus a very high EPSS score, though exploitation requires capturing a long-duration session and the flaw is not in KEV.

What it is

DES and Triple DES ciphers used in TLS, SSH, IPSec and other protocols have a birthday bound of roughly four billion blocks, allowing a birthday attack against long-duration encrypted sessions. An attacker who can capture enough ciphertext from a single long-lived session can recover cleartext data, as demonstrated against HTTPS using Triple DES in CBC mode (Sweet32).

Impact

An attacker gains partial recovery of cleartext from the affected session, exposing sensitive data carried over it. The CVSS vector shows confidentiality impact only, with no integrity or availability effect.

Attack surface

Reachable remotely over the network (AV:N) with no privileges and no user interaction required, per the CVSS vector. The attacker must be positioned to observe a long-duration session's ciphertext, such as a network man-in-the-middle.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high at 0.957 (99.9th percentile), indicating strong predicted exploitation activity. Reference tags are advisory and mailing-list entries only, with no public exploit tag supplied.

What to do

  • Patch or upgrade affected products (OpenSSL, Red Hat JBoss/Enterprise Linux, Python, Node.js, Cisco, Oracle) to versions that disable or deprecate DES/3DES cipher suites.
  • Disable DES and Triple DES cipher suites in TLS, SSH and IPSec configurations, preferring AES-based suites.
  • Limit session lifetimes and force rekeying so no single session approaches the four-billion-block birthday bound.
  • Audit exposed services for 3DES usage and remove it from allowed cipher lists at load balancers and reverse proxies.

Detection

  • Search TLS/SSH/IPSec configuration and handshake logs for negotiated DES or 3DES cipher suites.
  • Monitor for unusually long-lived encrypted sessions that could accumulate enough blocks for a birthday attack.
  • Alert on network captures or IDS signatures referencing Sweet32 or 3DES CBC session traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00011.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00012.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00021.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00029.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2017-01/msg00068.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00003.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00023.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00028.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2017-02/msg00032.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2017-05/msg00076.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00010.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2017-10/msg00011.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00032.html Mailing ListThird Party Advisory
http://packetstormsecurity.com/files/142756/IBM-Informix-Dynamic-Server-DLL-Injection-Code-Execution.html Third Party AdvisoryVDB Entry
http://rhn.redhat.com/errata/RHSA-2017-0336.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0337.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0338.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0462.html Third Party Advisory
http://seclists.org/fulldisclosure/2017/Jul/31 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2017/May/105 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2017/May/105 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2017/May/105 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2017/May/105 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2017/May/105 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2017/May/105 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2017/May/105 Mailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2017/May/105 Mailing ListThird Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=nas8N1021697 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21991482 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21995039 Third Party Advisory
http://www.debian.org/security/2016/dsa-3673 Third Party Advisory
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170322-01-openssl-en Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html PatchThird Party Advisory

Track CVE-2016-2183 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2026-21636Nodejs node.js improper access control vulnerabilityA flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even …EPSS 0.88%10.0CVE-2015-0278Fedoraproject fedora vulnerabilitylibuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.EPSS 3.2%10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 6.5%10.0CVE-2008-5031Python vulnerabilityMultiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer va…EPSS 3.0%10.0CVE-2006-3738OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher listOpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The …EPSS 49%analysed9.9CVE-2017-10202Oracle database vulnerabilityVulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily explo…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2016-2183), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.