Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27052
HistorySep 21, 2020 - 6:32 a.m.

Sweet32 Attack

2020-09-2106:32:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.005 Low

EPSS

Percentile

76.9%

OpenVPN is vulnerable to Sweet32 Attack. When using a 64-bit block cipher, it is easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a “Sweet32” attack.