Smurf Amplification in 2026: Pre-Auth ICMP Reflection via L2 Broadcast

CVE-1999-0513 is 27 years old. The mechanism is alive. A 2026 enterprise wireless controller with no uRPF, no directed broadcast filtering, and an ICMP Echo handler that reflects to any source address gives you Smurf amplification from L2 adjacency. This post documents the full chain.

June 5, 2026 · 8 min · JM00NJ

ArubaOS 8.13.2.0 Smurf Amplification & ICMP Reflection: Pre-Auth Attack via Missing uRPF (HPE Bug Bounty)

A 28-year-old vulnerability class — Smurf amplification — alive in an enterprise controller shipping in 2026. Two independent packet captures prove reflection. Bugcrowd called it expected behavior. No fix issued.

June 1, 2026 · 3 min · JM00NJ
DigitalOcean Referral Badge