H3-2020-0027¶
Vulnerable SSL Weak Ciphers
| Category | SECURITY_MISCONFIGURATION |
| Base Score | 0.1 |
Description¶
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Impact¶
An attacker can obtain plaintext data via a birthday attack against a long-duration encrypted session.