CVE-2016-2055 describes a critical arbitrary file read vulnerability in Xymon versions 4.1.x, 4.2.x, and 4.3.x before 4.3.25, specifically within the xymond component. This flaw allows unauthenticated remote attackers to access and read any file within the configuration directory by sending a crafted "config" command. Rated with a CVSSv3 score of 7.5 (HIGH), this vulnerability has a low attack complexity and requires no user interaction or privileges, enabling a high impact on confidentiality. The EPSS score of 0.67997 indicates a higher than average probability of exploitation. While there is no evidence of active exploitation in the wild, a Metasploit auxiliary module exists, demonstrating exploitability. Despite this, the vulnerability has garnered minimal community discussion and media coverage, suggesting it is not widely known or actively targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.0CPE matchmatch criteria | cpe:2.3:a:xymon:xymon:4.1.0:*:*:*:*:*:*:* | ||
4.1.1CPE matchmatch criteria | cpe:2.3:a:xymon:xymon:4.1.1:*:*:*:*:*:*:* | ||
4.1.2CPE matchmatch criteria | cpe:2.3:a:xymon:xymon:4.1.2:*:*:*:*:*:*:* | ||
4.1.2CPE matchmatch criteria | cpe:2.3:a:xymon:xymon:4.1.2:p1:*:*:*:*:*:* | ||
4.1.2CPE matchmatch criteria | cpe:2.3:a:xymon:xymon:4.1.2:p2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.