Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in the

advanced forwarding toolkit (evo-aftmand)

of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the

evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control.

Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC.

This issue affects Junos OS Evolved on PTX :


* from 24.4R2-EVO before 24.4R2-S3-EVO;
* from 25.2 before 25.2R2-EVO.
Published: 2026-07-09
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an Improper Check for Unusual or Exceptional Conditions (CWE-754) in Juniper Networks Junos OS Evolved’s advanced forwarding toolkit on PTX Series. An unauthenticated network-based attacker can continuously send ECMP routing updates that create unilist ECMP routes. The router incorrectly processes these updates, corrupting internal state and causing the evo engine to crash. The crash results in a denial-of-service that requires manual intervention, such as rebooting the system or restarting the FPC, to recover. The CVSS score is 8.2, indicating high severity. EPSS is <1%, indicating a very low but non-zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could send traffic that does not require user authentication to trigger the flaw. The likely attack vector is network-based traffic continuously sending routing updates that are typical in operational environments, leading to a crash of the evo-aftmand process. The impact would be a disruption of routing functions on the affected device, causing service outages until the system is rebooted or the FPC restarted.

Affected Systems

The affected vendor is Juniper Networks, specifically the Junos OS Evolved PTX Series. Vulnerable releases include any version of 24.4R2‑EVO that is earlier than 24.4R2‑S3‑EVO, and any version of 25.2 before 25.2R2‑EVO. The fix is included in releases 24.4R2‑S3‑EVO, 25.2R2‑EVO, 25.4R1‑EVO, and all subsequent updates.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score of <1% suggests that the probability of exploitation in the wild is low, though not zero. The vulnerability is not listed in CISA’s KEV catalog, meaning there are no known widespread active exploits. The attack vector is network-based; an unauthenticated attacker must continuously inject ECMP routing updates that create unilist ECMP routes. Successful exploitation requires continuous traffic that the router processes, which may occur in background management or mistimed routing protocols. If the conditions are met, the evo-aftmand process will crash, causing a denial of service until the device is rebooted or the FPC restarted.

Generated by OpenCVE AI on July 26, 2026 at 14:45 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS Evolved: 24.4R2-S3-EVO, 25.2R2-EVO, 25.4R1-EVO, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade Junos OS Evolved on all PTX Series devices to version 24.4R2‑S3‑EVO, 25.2R2‑EVO, 25.4R1‑EVO, or any later release that contains the fix.
  • After upgrading, reboot the FPC or the entire device to clear any corrupted state and reinitialize the PFE.
  • Monitor routing tables and PFE logs for sudden unilist ECMP changes and enable logging of routing update events to detect anomalous activity.

Generated by OpenCVE AI on July 26, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os Evolved
Vendors & Products Juniper Networks
Juniper Networks junos Os Evolved

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the evo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control. Unified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC. This issue affects Junos OS Evolved on PTX : * from 24.4R2-EVO before 24.4R2-S3-EVO; * from 25.2 before 25.2R2-EVO.
Title Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates results in PFE crash
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:U/V:C/RE:M/U:Green'}


Subscriptions

Juniper Networks Junos Os Evolved
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:22:17.928Z

Reserved: 2026-03-23T19:46:13.673Z

Link: CVE-2026-33794

cve-icon Vulnrichment

Updated: 2026-07-10T14:22:14.539Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T15:00:05Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions