Vulnerability record · CVE-2016-2183 · published 1 September 2016
CVE-2016-2183: DES/3DES Birthday Bound Flaw Enables Cleartext Recovery (Sweet32)
Redhat · Jboss Enterprise Application Platform
DES and Triple DES ciphers used in TLS, SSH, IPSec and other protocols have a birthday bound of roughly four billion blocks, allowing a birthday attack against long-duration encrypted sessions. An attacker who can capture enough ciphertext from a single long-lived session can recover cleartext data, as demonstrated against HTTPS using Triple DES in CBC mode (Sweet32).
Description
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with network reachability and high confidentiality impact, plus a very high EPSS score, though exploitation requires capturing a long-duration session and the flaw is not in KEV.
What it is
DES and Triple DES ciphers used in TLS, SSH, IPSec and other protocols have a birthday bound of roughly four billion blocks, allowing a birthday attack against long-duration encrypted sessions. An attacker who can capture enough ciphertext from a single long-lived session can recover cleartext data, as demonstrated against HTTPS using Triple DES in CBC mode (Sweet32).
Impact
An attacker gains partial recovery of cleartext from the affected session, exposing sensitive data carried over it. The CVSS vector shows confidentiality impact only, with no integrity or availability effect.
Attack surface
Reachable remotely over the network (AV:N) with no privileges and no user interaction required, per the CVSS vector. The attacker must be positioned to observe a long-duration session's ciphertext, such as a network man-in-the-middle.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high at 0.957 (99.9th percentile), indicating strong predicted exploitation activity. Reference tags are advisory and mailing-list entries only, with no public exploit tag supplied.
What to do
- Patch or upgrade affected products (OpenSSL, Red Hat JBoss/Enterprise Linux, Python, Node.js, Cisco, Oracle) to versions that disable or deprecate DES/3DES cipher suites.
- Disable DES and Triple DES cipher suites in TLS, SSH and IPSec configurations, preferring AES-based suites.
- Limit session lifetimes and force rekeying so no single session approaches the four-billion-block birthday bound.
- Audit exposed services for 3DES usage and remove it from allowed cipher lists at load balancers and reverse proxies.
Detection
- Search TLS/SSH/IPSec configuration and handshake logs for negotiated DES or 3DES cipher suites.
- Monitor for unusually long-lived encrypted sessions that could accumulate enough blocks for a birthday attack.
- Alert on network captures or IDS signatures referencing Sweet32 or 3DES CBC session traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-2183 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-2183), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.