Smurf Amplification in 2026: Pre-Auth ICMP Reflection via L2 Broadcast | CVE-1999-0513 & Enterprise VLAN

Smurf amplification requires three weaknesses simultaneously: no uRPF allows IP source spoofing, directed broadcast forwarding delivers the packet to all VLAN hosts, hosts reply to broadcast ICMP Echo. RFC 2644 fixed router-level directed broadcast. L2 broadcast domains are unaffected — the packet never crosses a router. Enterprise wireless VLANs with 50-100 APs and controllers become 50-100x amplifiers. ICMP processing is pre-authentication: no credentials, no session. Two-machine verification: attacker sends spoofed src=victim to broadcast, victim captures unsolicited Echo Replies. pcap-level proof included.

June 5, 2026 · 8 min · JM00NJ
Smurf Amplification in 2026: Pre-Auth ICMP Reflection via L2 Broadcast | CVE-1999-0513 & Enterprise VLAN

ArubaOS 8.13.2.0 Smurf Amplification & ICMP Reflection: Pre-Auth uRPF Missing + Broadcast Reply | HPE Bugcrowd N/A

ArubaOS 8.13.2.0 does not validate ICMP Echo Request source IPs against MAC/IP bindings or apply uRPF — attacker MAC with victim IP is accepted and replied to (CWE-290). Broadcast source IP (192.168.56.255) causes the controller to reply to ff:ff:ff:ff:ff:ff, delivering the reply to every host on the L2 segment (CWE-406). Two-machine evidence: Parrot OS attacker sends spoofed request, Windows victim receives unsolicited Echo Reply id=0xc101 confirmed in independent pcap. No ICMP request was sent from the victim. RFC 1122 §3.2.2.6 violation. Bugcrowd closed as expected behavior. No fix issued.

June 1, 2026 · 3 min · JM00NJ
ArubaOS 8.13.2.0 Smurf Amplification & ICMP Reflection: Pre-Auth uRPF Missing + Broadcast Reply | HPE Bugcrowd N/A
DigitalOcean Referral Badge