HIGH🇵🇱 Wersja polska

CVE-2026-33794

CVSS 8.2v4.0pub. 2026-07-09upd. 2026-07-13

An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control. Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC. This issue affects Junos OS Evolved on PTX : * from 24.4R2-EVO before 24.4R2-S3-EVO; * from 25.2 before 25.2R2-EVO.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Green
  • Juniper Junos Os Evolved

    OS
    Juniper
    24.425.2
  • Juniper Ptx10000

    HW
    Juniper
    all versions
  • Juniper Ptx10001

    HW
    Juniper
    all versions
  • Juniper Ptx10001 36mr

    HW
    Juniper
    all versions
  • Juniper Ptx100016

    HW
    Juniper
    all versions
  • Juniper Ptx10002

    HW
    Juniper
    all versions
  • Juniper Ptx10002 36qdd

    HW
    Juniper
    all versions
  • Juniper Ptx10002 60c

    HW
    Juniper
    all versions
  • Juniper Ptx10003

    HW
    Juniper
    all versions
  • Juniper Ptx10003 160c

    HW
    Juniper
    all versions
  • Juniper Ptx10003 80c

    HW
    Juniper
    all versions
  • Juniper Ptx10003 81cd

    HW
    Juniper
    all versions
  • Juniper Ptx10004

    HW
    Juniper
    all versions
  • Juniper Ptx1000 72q

    HW
    Juniper
    all versions
  • Juniper Ptx10008

    HW
    Juniper
    all versions
  • Juniper Ptx10016

    HW
    Juniper
    all versions
  • Juniper Ptx12008

    HW
    Juniper
    all versions
  • Juniper Ptx3000

    HW
    Juniper
    all versions
  • Juniper Ptx5000

    HW
    Juniper
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-21902CRITICAL9.3PL ✓same product

RCE jako root w Juniper Junos OS Evolved — błędne uprawnienia do krytycznego zasobu

CVE-2021-0211CRITICAL10.0PL ✓same product

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message

CVE-2026-33801HIGH7.1PL ✓same product

DoS w RPD Juniper Junos OS przez złośliwą aktualizację BGP

CVE-2025-59969HIGH7.1same product

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forward...

CVE-2026-21919HIGH7.1same product

An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Jun...