← Vulnerability feed

Vulnerability record · CVE-2016-6329 · published 31 January 2017

CVE-2016-6329: Openvpn information exposure vulnerability

Openvpn · Openvpn

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.

5.9 CVSS 3.0 Medium EPSS 5.9% · top 7.0% CWE-200 · Information exposureCWE-310 · CWE-310
5.9CVSS 3.0 base score, v2 4.3
5.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
17 Jun 2026Last modified by NVD

Description

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www-01.ibm.com/support/docview.wss?uid=nas8N1021697 Permissions RequiredThird Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21991482 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21995039 Third Party Advisory
http://www.securityfocus.com/bid/92631 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036695 Third Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf
https://community.openvpn.net/openvpn/wiki/SWEET32 Vendor Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369403 Third Party Advisory
https://security.gentoo.org/glsa/201611-02 Third Party Advisory
https://sweet32.info/ Technical DescriptionThird Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=nas8N1021697 Permissions RequiredThird Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21991482 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21995039 Third Party Advisory
http://www.securityfocus.com/bid/92631 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036695 Third Party AdvisoryVDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf
https://community.openvpn.net/openvpn/wiki/SWEET32 Vendor Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369403 Third Party Advisory
https://security.gentoo.org/glsa/201611-02 Third Party Advisory
https://sweet32.info/ Technical DescriptionThird Party Advisory

Track CVE-2016-6329 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-27903Openvpn unrestricted file upload vulnerabilityOpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in …EPSS 8.9%9.8CVE-2023-46850Openvpn use after free vulnerabilityUse after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buff…EPSS 2.0%9.8CVE-2022-0547Openvpn improper authentication vulnerabilityOpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of def…EPSS 3.6%9.8CVE-2017-12166Openvpn out-of-bounds write vulnerabilityOpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting …EPSS 3.6%9.1CVE-2025-12106Openvpn vulnerabilityInsufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addressesEPSS 0.56%9.1CVE-2024-5594Openvpn vulnerabilityOpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary d…EPSS 0.84%9.1CVE-2018-7544Openvpn vulnerabilityA cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without…EPSS 1.8%9.0CVE-2006-1629Openvpn vulnerabilityOpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment var…EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2016-6329), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.