For [PR207679](https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207679) we moved AES-CBC ciphers to the default list on the server for POLA/backwards compatibility reasons. Several years later, undo this in advance of FreeBSD 13.
OpenSSH 7.9p1 removed aes-cbc from the default client list.