HIGH🇬🇧 English

CVE-2026-33794

DoS w Juniper Junos OS Evolved – awaria procesu evo-aftmand przy unilist ECMP

CVSS 8.2v4.0pub. 2026-07-09upd. 2026-07-13

Podatność typu Improper Check for Unusual or Exceptional Conditions w komponencie advanced forwarding toolkit (evo-aftmand) systemów Juniper Networks Junos OS Evolved na urządzeniach z serii PTX umożliwia nieuwierzytelnionemu atakującemu doprowadzenie do awarii procesu evo-aftmand na PFE. Skutkiem jest odmowa usługi (DoS) wymagająca ręcznej interwencji — restartu systemu lub restartu FPC.

Pokaż oryginał (EN)

An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control. Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC. This issue affects Junos OS Evolved on PTX : * from 24.4R2-EVO before 24.4R2-S3-EVO; * from 25.2 before 25.2R2-EVO.

🤖 Analiza AI
Jak działa

Atakujący generuje ciągłe aktualizacje tras routingowych, które powodują powstawanie tras unilist ECMP — specyficznego zachowania ECMP, gdzie wiele tras o równym koszcie współdzieli jeden logiczny wpis listy następnego przeskoku. W wyniku błędu w przetwarzaniu takich aktualizacji dochodzi do wewnętrznej korupcji stanu, szczególnie w dużych wdrożeniach z unilist ECMP. Prowadzi to do awarii procesu evo-aftmand i wygenerowania zrzutu core (evo-aftmand-bx). Warunki pomyślnego wykorzystania podatności zależą od sekwencji zdarzeń częściowo poza bezpośrednią kontrolą atakującego.

Skutki

Atakujący może doprowadzić do trwałej awarii procesu evo-aftmand na PFE, powodując odmowę usługi (DoS) na urządzeniu. Przywrócenie działania wymaga ręcznej interwencji — restartu systemu lub restartu FPC.

Mitygacja

Należy zaktualizować Junos OS Evolved do wersji 24.4R2-S3-EVO lub nowszej (dla gałęzi 24.4R2) albo do wersji 25.2R2-EVO lub nowszej (dla gałęzi 25.2). Szczegóły dostępne w poradniku producenta pod adresem https://supportportal.juniper.net/JSA110073.

Kogo dotyczy

Juniper Networks Junos OS Evolved na urządzeniach PTX Series (PTX1000-72Q, PTX10000, PTX10001): wersje od 24.4R2-EVO przed 24.4R2-S3-EVO oraz wersje od 25.2 przed 25.2R2-EVO.

Uwagi

Podatność wymaga spełnienia sekwencji zdarzeń częściowo niezależnych od atakującego (AT:P w wektorze CVSS 4.0), co obniża praktyczną exploitowalność. W środowiskach dużych wdrożeń ECMP unilist ryzyko jest istotnie wyższe. Odzyskanie systemu po awarii wymaga ręcznej interwencji operatora.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Green
  • Juniper Junos Os Evolved

    OS
    Juniper
    24.425.2
  • Juniper Ptx10000

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10001

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10001 36mr

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx100016

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10002

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10002 36qdd

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10002 60c

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10003

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10003 160c

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10003 80c

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10003 81cd

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10004

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx1000 72q

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10008

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx10016

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx12008

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx3000

    HW
    Juniper
    wszystkie wersje
  • Juniper Ptx5000

    HW
    Juniper
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-21902CRITICAL9.3PL ✓ten sam produkt

RCE jako root w Juniper Junos OS Evolved — błędne uprawnienia do krytycznego zasobu

CVE-2021-0211CRITICAL10.0PL ✓ten sam produkt

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message

CVE-2026-33801HIGH7.1PL ✓ten sam produkt

DoS w RPD Juniper Junos OS przez złośliwą aktualizację BGP

CVE-2025-59969HIGH7.1ten sam produkt

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forward...

CVE-2026-21919HIGH7.1ten sam produkt

An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Jun...