CVE-2016-2183: Cisco Content Security Management Appliance

High severity, CVSS 7.5. EPSS: 94.7% chance of exploitation in the next 30 days.

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

Affected products

  • Cisco Content Security Management Appliance: version 9.6.6-068 only; version 9.7.0-006 only
  • Node.js Node.js: from 0.10.0, before 0.10.47 (fixed in 0.10.47); from 0.12.0, before 0.12.16 (fixed in 0.12.16); from 4.0.0, before 4.1.2 (fixed in 4.1.2); from 4.2.0, before 4.6.0 (fixed in 4.6.0); from 6.0.0, before 6.7.0 (fixed in 6.7.0)
  • OpenSSL OpenSSL: version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; version 1.0.1f only; …
  • Oracle Database: version 11.2.0.4 only; version 12.1.0.2 only
  • Python Python: from 2.7.0, before 2.7.13 (fixed in 2.7.13); from 3.4.0, before 3.4.7 (fixed in 3.4.7); from 3.5.0, before 3.5.3 (fixed in 3.5.3)
  • Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat JBoss Enterprise Application Platform: version 6.0.0 only
  • Red Hat JBoss Enterprise Web Server: version 1.0.0 only; version 2.0.0 only
  • Red Hat JBoss Web Server: version 3.0 only

Published 2016-09-01. Last modified 2026-06-17.