An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control. Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC. This issue affects Junos OS Evolved on PTX : * from 24.4R2-EVO before 24.4R2-S3-EVO; * from 25.2 before 25.2R2-EVO.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:GreenJuniper Junos Os Evolved
OSJuniper24.425.2Juniper Ptx10000
HWJuniperall versionsJuniper Ptx10001
HWJuniperall versionsJuniper Ptx10001 36mr
HWJuniperall versionsJuniper Ptx100016
HWJuniperall versionsJuniper Ptx10002
HWJuniperall versionsJuniper Ptx10002 36qdd
HWJuniperall versionsJuniper Ptx10002 60c
HWJuniperall versionsJuniper Ptx10003
HWJuniperall versionsJuniper Ptx10003 160c
HWJuniperall versionsJuniper Ptx10003 80c
HWJuniperall versionsJuniper Ptx10003 81cd
HWJuniperall versionsJuniper Ptx10004
HWJuniperall versionsJuniper Ptx1000 72q
HWJuniperall versionsJuniper Ptx10008
HWJuniperall versionsJuniper Ptx10016
HWJuniperall versionsJuniper Ptx12008
HWJuniperall versionsJuniper Ptx3000
HWJuniperall versionsJuniper Ptx5000
HWJuniperall versions
Related vulnerabilities
RCE jako root w Juniper Junos OS Evolved — błędne uprawnienia do krytycznego zasobu
Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message
DoS w RPD Juniper Junos OS przez złośliwą aktualizację BGP
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forward...
An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Jun...