Considering Cavium is in a bulk of all hardware appliances (networking/security) and it's related to chip firmware and many organizations are bad at updating software on hardware... My guess is that even though he's scanning for vulnerable services - that doesn't actually expose the true amount of servers vulnerable.
If you think about corporate networks that are doing SSL/TLS decrypt these boxes that are the corporate owned MitM will be vulnerable to this since the hardware is basically forward-proxying the users session. That would mean the connection between the appliance and the service would be vulnerable - something you can't scan for via something like the prober he mentions.
If you think about corporate networks that are doing SSL/TLS decrypt these boxes that are the corporate owned MitM will be vulnerable to this since the hardware is basically forward-proxying the users session. That would mean the connection between the appliance and the service would be vulnerable - something you can't scan for via something like the prober he mentions.
Very interesting indeed...