CVE-2025-59969 PUBLISHED

Junos OS Evolved: QFX5000 Series and PTX Series: An attacker sending crafted multicast packets will cause evo-aftmand / evo-pfemand to crash and restart

Assigner: juniper
Reserved: 23.09.2025 Published: 09.04.2026 Updated: 09.04.2026

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on PTX Series or QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).An attacker sending crafted multicast packets will cause line cards running evo-aftmand/evo-pfemand to crash and restart or non-line card devices to crash and restart. Continued receipt and processing of these packets will sustain the Denial of Service (DoS) condition.

This issue affects Junos OS Evolved PTX Series:

  • All versions before 22.4R3-S8-EVO,
  • from 23.2 before 23.2R2-S5-EVO,
  • from 23.4 before 23.4R2-EVO,
  • from 24.2 before 24.2R2-EVO,
  • from 24.4 before 24.4R2-EVO.

This issue affects Junos OS Evolved on QFX5000 Series:

  • 22.2-EVO version before 22.2R3-S7-EVO,
  • 22.4-EVO version before 22.4R3-S7-EVO,
  • 23.2-EVO versions before 23.2R2-S4-EVO,
  • 23.4-EVO versions before 23.4R2-S5-EVO,
  • 24.2-EVO versions before 24.2R2-S1-EVO,
  • 24.4-EVO versions before 24.4R1-S3-EVO, 24.4R2-EVO.

This issue does not affect Junos OS Evolved on QFX5000 Series versions before: 21.2R2-S1-EVO, 21.2R3-EVO, 21.3R2-EVO, 21.4R1-EVO, and 22.1R1-EVO.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:U/V:C/RE:M/U:Amber
CVSS Score: 7.1

Product Status

Vendor Juniper Networks
Product Junos OS Evolved
Versions Default: unaffected
  • affected from 0 to 22.4R3-S8-EVO (excl.)
  • affected from 23.2 to 23.2R2-S5-EVO (excl.)
  • affected from 23.4 to 23.4R2-EVO (excl.)
  • affected from 24.2 to 24.2R2-EVO (excl.)
  • affected from 24.4 to 24.4R2-EVO (excl.)
Vendor Juniper Networks
Product Junos OS Evolved
Versions Default: unaffected
  • affected from 22.2 to 22.2R3-S7-EVO (excl.)
  • affected from 22.4 to 22.4R3-S7-EVO (excl.)
  • affected from 23.2 to 23.2R2-S4-EVO (excl.)
  • affected from 23.4 to 23.4R2-S5-EVO (excl.)
  • affected from 24.2 to 24.2R2-S1-EVO (excl.)
  • affected from 24.4 to 24.4R1-S3-EVO, 24.4R2-EVO (excl.)

Affected Configurations

Required Configuration for Exposure: 

[ protocols mld ] or   [ protocols pim ]

Exploits

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

Workarounds

There are no known workarounds for this issue.

Solutions

The following software releases have been updated to resolve this specific issue: For PTX Series: 22.4R3-S8-EVO, 23.2R2-S5-EVO, 23.4R2-EVO, 24.2R2-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases. For QFX5000 Series: 22.2R3-S7-EVO, 22.4R3-S7-EVO, 23.2R2-S4-EVO, 23.4R2-S5-EVO, 24.2R2-S1-EVO, 24.4R1-S3-EVO, 24.4R2-EVO, 25.2R1-EVO, and all subsequent releases.

References

Problem Types

  • CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE