Actually, why is that an SA and not an EN?
I don't see any particular security issue other than an echo reply can be triggered from a local broadcast domain machine. Yes it is a firewall bypass but nothing malicious can be done with it.
If this is an SA, then there are definitely ENs that should have been an SA.