PT-2026-56926 · Juniper Networks · Junos Evolved
CVE-2026-33794
·
Published
2026-07-09
·
Updated
2026-07-13
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Junos OS Evolved on PTX versions 24.4R2-EVO through 24.4R2-S2-EVO
Junos OS Evolved on PTX versions 25.2 through 25.2R1-EVO
Description
An improper check for unusual or exceptional conditions in the advanced forwarding toolkit (evo-aftmand) allows an unauthenticated network-based attacker to cause a Denial-of-Service (DoS). By generating continuous routing updates that result in unilist ECMP routes, an attacker can trigger internal state corruption, causing the
evo-aftmand process on the PFE to crash. Unified list (unilist) ECMP routes are a behavior where multiple equal-cost routes share a single logical next-hop list entry, allowing the router to load balance traffic across that list. Recovery requires manual intervention via a system reboot or restarting the FPC.Recommendations
Update Junos OS Evolved on PTX versions 24.4R2-EVO through 24.4R2-S2-EVO to version 24.4R2-S3-EVO.
Update Junos OS Evolved on PTX versions 25.2 through 25.2R1-EVO to version 25.2R2-EVO.
Fix
DoS
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos Evolved