5.9
CVE-2016-6329
- EPSS 5.94%
- Veröffentlicht 31.01.2017 22:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.94% | 0.923 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf
http://www-01.ibm.com/support/docview.wss?uid=swg21995039
http://www-01.ibm.com/support/docview.wss?uid=nas8N1021697
http://www-01.ibm.com/support/docview.wss?uid=swg21991482
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369403
https://sweet32.info/
http://www.securityfocus.com/bid/92631
http://www.securitytracker.com/id/1036695
https://community.openvpn.net/openvpn/wiki/SWEET32
https://security.gentoo.org/glsa/201611-02