CVE-2025-59969: Junos OS Evolved: QFX5000 Series and PTX Series: An attacker sending crafted multicast packets will cause evo-aftmand / evo-pfemand to crash and restart
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on PTX Series or QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).An attacker sending crafted multicast packets will cause line cards running evo-aftmand/evo-pfemand to crash and restart or non-line card devices to crash and restart. Continued receipt and processing of these packets will sustain the Denial of Service (DoS) condition.
This issue affects Junos OS Evolved PTX Series:
All versions before 22.4R3-S8-EVO, from 23.2 before 23.2R2-S5-EVO, from 23.4 before 23.4R2-EVO, from 24.2 before 24.2R2-EVO, from 24.4 before 24.4R2-EVO.
This issue affects Junos OS Evolved on QFX5000 Series:
22.2-EVO version before 22.2R3-S7-EVO, 22.4-EVO version before 22.4R3-S7-EVO, 23.2-EVO versions before 23.2R2-S4-EVO, 23.4-EVO versions before 23.4R2-S5-EVO, 24.2-EVO versions before 24.2R2-S1-EVO, 24.4-EVO versions before 24.4R1-S3-EVO, 24.4R2-EVO.
This issue does not affect Junos OS Evolved on QFX5000 Series versions before: 21.2R2-S1-EVO, 21.2R3-EVO, 21.3R2-EVO, 21.4R1-EVO, and 22.1R1-EVO.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59969?
CVE-2025-59969 is classified as a security vulnerability with high severity due to its potential to crash and restart critical services.
How do I fix CVE-2025-59969?
To mitigate CVE-2025-59969, update your Junos OS Evolved software to the latest version as specified by Juniper Networks.
What systems are affected by CVE-2025-59969?
CVE-2025-59969 affects Junos OS Evolved on the QFX5000 and PTX Series, specifically versions before the latest security updates.
What type of vulnerability is CVE-2025-59969?
CVE-2025-59969 is a Classic Buffer Overflow vulnerability that occurs due to improper input size checking in the advanced forwarding toolkit.
Are there any workarounds for CVE-2025-59969?
At this time, the recommended action is to apply the latest software patches rather than relying on temporary workarounds.