Back

CVE-2016-9565

CRITICAL

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.

Published: Dec 15, 2016 Modified: Jun 17, 2026
CWE-284

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
nagios nagios *

GitHub Security Advisory GHSA-828p-3vwg-wc22

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 22.68%

Top 3% most likely to be exploited

Threat Score 46 / 100

Data Sources

NVD EPSS GitHub