ExtremeZ-IP Multiple Remote Flaws
Medium Nessus Network Monitor Plugin ID 4371
SynopsisThe remote host is vulnerable to multiple attack vectors.
DescriptionThe remote host is running ExtremeZ-IP.
ExtremeZ-IP is a software product that allows for file sharing and printing between Mac and Windows machines. This version is reported to be vulnerable to a number of remote flaws. Specifically, the server is vulnerable to a denial of service attack within the Service Location Protocol (SLP) and Apple Filing Protocol (AFP). An attacker exploiting either of these two flaws would send malformed data to the service, resulting in a loss of service availability. The third flaw is a directory traversal flaw that would allow an attacker the ability to download certain files (those with an extension of gif, png, jpg, xml, ico, zip, and html) from outside the defined web directory. This can lead to a loss of confidential data.
SolutionUpgrade to a version higher than 5.1.2x15.