Juniper Networks Junos OS Evolved Buffer Overflow Vulnerability in PTX and QFX5000 Series Allowing Denial-of-Service

Vulnerability

A classic buffer overflow vulnerability has been identified in the advanced forwarding toolkit components 'evo-aftmand' and 'evo-pfemand' of Juniper Networks Junos OS Evolved. This vulnerability affects PTX Series and QFX5000 Series devices, allowing an unauthenticated, adjacent attacker to cause a denial-of-service condition. By sending crafted multicast packets, an attacker can disrupt line cards running the vulnerable components, causing them to crash and restart. Non-line card devices will also experience a crash and restart. The denial-of-service condition can be sustained with the continued receipt and processing of these packets. The vulnerability affects several versions and ranges of Junos OS Evolved on both PTX Series and QFX5000 Series.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing affected devices to crash and restart. On QFX5000 Series, this vulnerability does not affect versions prior to 21.2R2-S1-EVO, 21.2R3-EVO, 21.3R2-EVO, 21.4R1-EVO, and 22.1R1-EVO.

Remediation

Users can upgrade to Junos OS Evolved versions 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-EVO, 24.2R2-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases for PTX Series. For QFX5000 Series, users can upgrade to versions 22.2R3-S7-EVO, 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases.

Added: Apr 10, 2026, 1:06 AM
Updated: Apr 10, 2026, 1:06 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
4.5
remediation
7.7
relevance
5.6
threat
0.0
urgency
5.7
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.