ExtremeZ-IP Multiple Remote Flaws

Medium Nessus Network Monitor Plugin ID 4371


The remote host is vulnerable to multiple attack vectors.


The remote host is running ExtremeZ-IP.

ExtremeZ-IP is a software product that allows for file sharing and printing between Mac and Windows machines. This version is reported to be vulnerable to a number of remote flaws. Specifically, the server is vulnerable to a denial of service attack within the Service Location Protocol (SLP) and Apple Filing Protocol (AFP). An attacker exploiting either of these two flaws would send malformed data to the service, resulting in a loss of service availability. The third flaw is a directory traversal flaw that would allow an attacker the ability to download certain files (those with an extension of gif, png, jpg, xml, ico, zip, and html) from outside the defined web directory. This can lead to a loss of confidential data.


Upgrade to a version higher than 5.1.2x15.

See Also




Plugin Details

Severity: Medium

ID: 4371

File Name: 4371.prm

Family: Web Servers

Published: 2008/02/11

Modified: 2016/11/23

Dependencies: 4369

Nessus ID: 30253

Risk Information

Risk Factor: Medium


Base Score: 6.4

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C


Base Score: 6.4

Temporal Score: 5.9


Temporal Vector: CVSS3#E:F/RL:O/RC:C

Reference Information

CVE: CVE-2008-0758, CVE-2008-0759, CVE-2008-0767

BID: 27718