CWE-290 Layer 3: IP Source Spoofing via Missing uRPF | Smurf Amplification, ICMP Leak & Pre-Auth Reflection in ArubaOS

uRPF performs reverse routing lookup on every incoming packet’s source address — if the packet arrived on the wrong interface, it’s spoofed and dropped. When uRPF is disabled (the enterprise wireless default due to asymmetric routing), any host on the L2 segment can claim any source IP unconditionally. This is CWE-290 at Layer 3. Three confirmed attack classes in ArubaOS AOS-8: Smurf amplification (spoofed src → broadcast → victim flood), ICMP Timestamp leak (impersonate trusted management IP → elicit timestamp response), pre-auth reflection (use controller as intermediary). Single-packet pcap signature included. Linux sysctl and Cisco IOS uRPF configuration provided.

June 7, 2026 · 10 min · JM00NJ

ArubaOS 8.13.2.0 Pre-Auth ICMP Buffer Over-read: EtherLeak via TTL=0 + IP Total Length | HPE Bugcrowd

Three compounding weaknesses in ArubaOS 8.13.2.0 ICMP handler: IP Total Length over-read reads 18 bytes past actual frame data into Ethernet padding (CWE-126); TTL=0 packets are processed and replied to in RFC 791 violation (CWE-1284); ICMP checksums are never validated (CWE-354). TTL=0 makes extraction invisible — routers don’t forward, IDS ignores, firewalls don’t log. 27/27 crafted probes confirmed. On physical AOS-8 hardware with active management traffic, the 18-byte DMA region contains previous frame fragments. CVE-2003-0001 and CVE-2021-3031 accepted on identical mechanism without physical hardware PoC.

June 1, 2026 · 4 min · JM00NJ
DigitalOcean Referral Badge