CVE-2016-2055

HIGH

Xymon Daemon Gather Information

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-2055. PoCs published by Markus Krell, bcoles, including Metasploit module auxiliary/gather/xymon_info.

AI-analyzed exploit summary This Metasploit module exploits CVE-2016-2055 to retrieve sensitive configuration files (including password hashes) from Xymon servers before 4.3.25 or those with `ALLOWALLCONFIGFILES` enabled. It gathers server info, host lists, and client logs via unauthenticated TCP commands.

Description

xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command.

Exploits (1)

metasploit WORKING POC
by Markus Krell, bcoles · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/xymon_info.rb

This Metasploit module exploits CVE-2016-2055 to retrieve sensitive configuration files (including password hashes) from Xymon servers before 4.3.25 or those with `ALLOWALLCONFIGFILES` enabled. It gathers server info, host lists, and client logs via unauthenticated TCP commands.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Xymon (formerly Hobbit) < 4.3.25
No auth needed
Prerequisites: Network access to Xymon daemon (TCP/1984) · Vulnerable Xymon version or misconfiguration
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/537522/100/0/threaded
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3495
Patch x_refsource_confirm
https://sourceforge.net/p/xymon/code/7890/

Scores

CVSS v3 7.5
EPSS 0.1785
EPSS Percentile 96.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (33)
debian/debian_linux 8.0
xymon/xymon 4.1.0
xymon/xymon 4.1.1
xymon/xymon 4.1.2 (3 CPE variants)
xymon/xymon 4.2 alfa (3 CPE variants)
xymon/xymon 4.2.0
xymon/xymon 4.2.2 (2 CPE variants)
xymon/xymon 4.2.3 (2 CPE variants)
xymon/xymon 4.3.0 (5 CPE variants)
xymon/xymon 4.3.1
... and 23 more
Published Apr 13, 2016
Tracked Since Feb 18, 2026