CVE-2016-9566 is a local privilege escalation vulnerability affecting Nagios Core versions prior to 4.2.4. It allows local users belonging to the 'nagios' group to gain root privileges through a symlink attack on the log file, and can be chained with CVE-2016-9565 for remote exploitation. This vulnerability is rated as High severity (CVSS 7.8), indicating a significant risk of complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog, public exploit code exists (EDB-40921), and there has been notable community discussion and media coverage, including a demonstration video, suggesting active awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.3CPE matchmatch criteria | cpe:2.3:a:nagios:nagios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.