Database/Firmware, BMC & network fabric
Juniper Junos OS Packet Forwarding Engine (VXLAN + ICMP): A high rate of specific ICMP traffic to a device with VXLAN
Impact
A high rate of specific ICMP traffic to a device with VXLAN configured deadlocks the Packet Forwarding Engine and leaves the switch unresponsive — recovery requires a manual restart, so it does not self-heal. On a VXLAN/EVPN GPU fabric this is a tenant-reachable way to require hands-on intervention on a leaf, and ICMP is not something most operators filter inside the fabric.
Who can reach it
Unauthenticated, network-based — an attacker able to send ICMP at rate toward a VXLAN-configured Junos device. Any tenant workload qualifies.
What to do
Junos upgrade plus reboot. Immediate mitigation is a control-plane policer rate-limiting ICMP toward the device — a live config change, no downtime, and it converts a manual-restart outage into a throttled nuisance. Related Junos VXLAN PFE issues: CVE-2023-36835 (QFX10000, PFE wedge on a valid IP packet routed over a VXLAN tunnel) and CVE-2022-22171.
References
Related entries
- IBM OpenBMC bmcweb HTTPS server (FW1050.00 - FW1050.10): Certain URIs on IBM's OpenBMC-derived bmcweb returnCVE-2024-31916 · IBM OpenBMC bmcweb HTTPS server (FW1050.00 - FW1050.10)High
- IBM OpenBMC default password and session management (FW1020, FW1030, FW1050): The combination of a shipped defaultCVE-2024-35124 · IBM OpenBMC default password and session management (FW1020, FW1030, FW1050)High
- Supermicro BIOS (arbitrary memory write, X11DPH series): Arbitrary memory write from firmware context on X11DPH boardsCVE-2024-36433 · Supermicro BIOS (arbitrary memory write, X11DPH series)High
- Supermicro BIOS SMM callout (X11DPH-T / X11DPH-Tq): Execution in System Management Mode, the most privileged executionCVE-2024-36434 · Supermicro BIOS SMM callout (X11DPH-T / X11DPH-Tq)High
- Dell SmartFabric OS10 (uncontrolled resource consumption): A remote unauthenticated host can exhaust resources on anCVE-2024-37125 · Dell SmartFabric OS10 (uncontrolled resource consumption)High
- Sunbird DCIM dcTrack v9.1.2 - ticket location RBAC: Incorrect access control lets an attacker create or update ticketsCVE-2024-37775 · Sunbird DCIM dcTrack v9.1.2 - ticket location RBACHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.