Support on SonicWall Products, Services and Solutions
Browse Knowledgebase by Category
SWEET32 vulnerability of 64 bit ciphers (3DES/Blowfish) - CVE-2016-2183
03/26/2020 110 15302
A vulnerability scan on the HTTPS management port or SSL-VPN port shows that the SonicWall is vulnerable to the SWEET 32 attack on 64 bit ciphers (3DES/Blowfish)
Unaffected firmware versions:
- 220.127.116.11-32n and above
- 18.104.22.168-20n and above
- 22.214.171.124-23n and above
- 126.96.36.199-10o and above
Affected firmware versions:
- 188.8.131.52-26n and below
- 184.108.40.206-41n and below
- 220.127.116.11-27n and below
- 18.104.22.168-2o and below
- 22.214.171.124-13o and below
Previous SonicWall firmware allows the use of 3DES for TLS connections and is therefore vulnerable to the SWEET 32 attack described in CVE-2016-2183.
This issue has been fixed in the latest general release firmware.
To download release notes and firmware please visit www.mysonicwall.com. To upgrade SonicOS firmware please see How to Upgrade SonicOS Firmware.