Recently our our PCI Compliance vendor is failing our Exchange 2013 server on port 25 & 443 for the Sweet32 vulnerability.
Any input on mitigating the issue (without breaking mail flow) would be appreciated.
below is the ciphers we are getting flagged for.
Block cipher algorithms with block size of 64 bits (like DES and 3DES) birthday attack known as Sweet32Cipher Suite
TLSv1 : DES-CBC3-SHA
TLSv1_1 : DES-CBC3-SHA
TLSv1_2 : DES-CBC3-SHA
Thanks in advance!