5.9

CVE-2016-6329

Medienbericht
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openvpn ≫ Openvpn Version <= 2.3.14
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.94% 0.923
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
10.07.2026 14:07
https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf
http://www-01.ibm.com/support/docview.wss?uid=swg21995039
Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=nas8N1021697
Third Party Advisory
Permissions Required
http://www-01.ibm.com/support/docview.wss?uid=swg21991482
Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05369403
Third Party Advisory
https://sweet32.info/
Third Party Advisory
Technical Description
http://www.securityfocus.com/bid/92631
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1036695
Third Party Advisory
VDB Entry
https://community.openvpn.net/openvpn/wiki/SWEET32
Vendor Advisory
https://security.gentoo.org/glsa/201611-02
Third Party Advisory