Database/Firmware, BMC & network fabric
Juniper Junos OS Packet Forwarding Engine (VXLAN + ICMP): A high rate of specific ICMP traffic to a device with VXLAN
Impact
A high rate of specific ICMP traffic to a device with VXLAN configured deadlocks the Packet Forwarding Engine and leaves the switch unresponsive — recovery requires a manual restart, so it does not self-heal. On a VXLAN/EVPN GPU fabric this is a tenant-reachable way to require hands-on intervention on a leaf, and ICMP is not something most operators filter inside the fabric.
Who can reach it
Unauthenticated, network-based — an attacker able to send ICMP at rate toward a VXLAN-configured Junos device. Any tenant workload qualifies.
What to do
Junos upgrade plus reboot. Immediate mitigation is a control-plane policer rate-limiting ICMP toward the device — a live config change, no downtime, and it converts a manual-restart outage into a throttled nuisance. Related Junos VXLAN PFE issues: CVE-2023-36835 (QFX10000, PFE wedge on a valid IP packet routed over a VXLAN tunnel) and CVE-2022-22171.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.