{"id":"CVE-2016-2183","description":"The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a \"Sweet32\" attack.","cvssScore":7.5,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cvssMetrics":[{"version":"3.1","score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"3.1","score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","sourceName":"CISA-ADP","type":"Secondary"},{"version":"2.0","score":5,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-200"],"resolved":"OUT-OF-SCOPE","published":"2016-09-01","lastModified":"2026-06-17","affectedProducts":[{"vendor":"redhat","product":"jboss enterprise application platform","version":"6.0.0"},{"vendor":"redhat","product":"jboss enterprise web server","version":"1.0.0"},{"vendor":"redhat","product":"jboss enterprise web server","version":"2.0.0"},{"vendor":"redhat","product":"jboss web server","version":"3.0"},{"vendor":"redhat","product":"enterprise linux","version":"5.0"},{"vendor":"redhat","product":"enterprise linux","version":"6.0"},{"vendor":"redhat","product":"enterprise linux","version":"7.0"},{"vendor":"python","product":"python","versionStart":"\u003e=2.7.0","versionEnd":"\u003c2.7.13"},{"vendor":"python","product":"python","versionStart":"\u003e=3.4.0","versionEnd":"\u003c3.4.7"},{"vendor":"python","product":"python","versionStart":"\u003e=3.5.0","versionEnd":"\u003c3.5.3"},{"vendor":"cisco","product":"content security management appliance","version":"9.6.6-068"},{"vendor":"cisco","product":"content security management appliance","version":"9.7.0-006"},{"vendor":"openssl","product":"openssl","version":"1.0.1a"},{"vendor":"openssl","product":"openssl","version":"1.0.1b"},{"vendor":"openssl","product":"openssl","version":"1.0.1c"},{"vendor":"openssl","product":"openssl","version":"1.0.1d"},{"vendor":"openssl","product":"openssl","version":"1.0.1e"},{"vendor":"openssl","product":"openssl","version":"1.0.1f"},{"vendor":"openssl","product":"openssl","version":"1.0.1g"},{"vendor":"openssl","product":"openssl","version":"1.0.1h"}],"totalAffectedProducts":9,"references":[{"url":"https://access.redhat.com/errata/RHSA-2017:0462","source":"redhat","tags":["ADVISORY","RHSA-2017:0462"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1369383","source":"redhat","tags":["REPORT","RHSA-2017:0462"]},{"url":"https://access.redhat.com/security/cve/CVE-2016-2183","source":"redhat","tags":["REPORT","RHSA-2017:0462"]},{"url":"https://access.redhat.com/errata/RHSA-2016:1940","source":"redhat","tags":["ARTICLE","RHSA-2017:0462"]},{"url":"http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10759","source":"secalert@redhat.com","tags":["Third Party Advisory"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00022.html","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00023.html","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00024.html","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00031.html","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00005.html","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]}],"reasoning":{"decidingSource":"h2-out-of-scope-with-cpe","decidingReason":"Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"matched","status":"OUT-OF-SCOPE","detail":"Found in legacy manual classifications","decisive":true}]},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update October 2021","releaseType":"CPU","quarter":"2021-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2021.html","products":[{"product":"Oracle Siebel CRM","component":"EAI, SWSE (OpenSSL)","affectedVersions":"21.9 and prior"}]},{"advisory":"Oracle Critical Patch Update October 2017","releaseType":"CPU","quarter":"2017-Q4","url":"https://www.oracle.com/security-alerts/cpuoct2017.html","products":[{"product":"Oracle Fusion Middleware","component":"OSSL Module","affectedVersions":"11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0"}]},{"advisory":"Oracle Critical Patch Update July 2017","releaseType":"CPU","quarter":"2017-Q3","url":"https://www.oracle.com/security-alerts/cpujul2017.html","products":[{"product":"Oracle Database Server","component":"Real Application Clusters","affectedVersions":"11.2.0.4, 12.1.0.2"}]},{"advisory":"Oracle Critical Patch Update January 2017","releaseType":"CPU","quarter":"2017-Q1","url":"https://www.oracle.com/security-alerts/cpujan2017.html","products":[{"product":"Oracle Java SE","component":"Java SE, Java SE Embedded","affectedVersions":"Java SE: 6u131, 7u121, 8u112; Java SE Embedded: 8u111"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"not-needed","type":"none"},"review":{"state":"human","basis":"manual-review"}},"h2Comments":"## Manual Classification Context\n\n\n**Labels:** HTTPS, SWEET32, MULTIPLE, SSL/TLS, SEE NOTE 3, NO AUTH REMOTE EXPLOIT, OSSL MODULE, TLS, SWSE (OPENSSL), EAI\n\n**Products:** TLS SSH, SSL/TLS, DES CIPHER, IPSEC PROTOCOLS, SIEBEL UI FRAMEWORK, ORACLE SIEBEL CRM","exploits":[{"source":"github-poc","url":"https://github.com/ZakyHermawan/Simple-Sweet32","title":"Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183)","date":"2025-12-13T05:36:57Z"}],"signals":{"hasPOC":true,"pocCount":1,"pocSources":["github-poc"],"firstPOCDate":"2025-12-13T05:36:57Z"},"kev":{"inKEV":false},"epss":{"available":true,"score":0.95707,"percentile":0.99868},"ssvc":{"available":true,"exploitation":"poc","automatable":"yes","technicalImpact":"partial"}}