Impact
This vulnerability is an Improper Check for Unusual or Exceptional Conditions (CWE-754) in Juniper Networks Junos OS Evolved’s advanced forwarding toolkit on PTX Series. An unauthenticated network-based attacker can continuously send ECMP routing updates that create unilist ECMP routes. The router incorrectly processes these updates, corrupting internal state and causing the evo engine to crash. The crash results in a denial-of-service that requires manual intervention, such as rebooting the system or restarting the FPC, to recover. The CVSS score is 8.2, indicating high severity. EPSS is <1%, indicating a very low but non-zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could send traffic that does not require user authentication to trigger the flaw. The likely attack vector is network-based traffic continuously sending routing updates that are typical in operational environments, leading to a crash of the evo-aftmand process. The impact would be a disruption of routing functions on the affected device, causing service outages until the system is rebooted or the FPC restarted.
Affected Systems
The affected vendor is Juniper Networks, specifically the Junos OS Evolved PTX Series. Vulnerable releases include any version of 24.4R2‑EVO that is earlier than 24.4R2‑S3‑EVO, and any version of 25.2 before 25.2R2‑EVO. The fix is included in releases 24.4R2‑S3‑EVO, 25.2R2‑EVO, 25.4R1‑EVO, and all subsequent updates.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score of <1% suggests that the probability of exploitation in the wild is low, though not zero. The vulnerability is not listed in CISA’s KEV catalog, meaning there are no known widespread active exploits. The attack vector is network-based; an unauthenticated attacker must continuously inject ECMP routing updates that create unilist ECMP routes. Successful exploitation requires continuous traffic that the router processes, which may occur in background management or mistimed routing protocols. If the conditions are met, the evo-aftmand process will crash, causing a denial of service until the device is rebooted or the FPC restarted.
OpenCVE Enrichment