---
id: CVE-2025-59969
title: >-
  A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
  vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of
  Juniper Networks Junos OS Evolved on PTX Series or QFX5000 Series allows an
  unauthenti…
summary: >-
  A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
  vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of
  Juniper Networks Junos OS Evolved on PTX Series or QFX5000 Series allows an
  unauthenti…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-120
vendor: juniper
product: junos_os_evolved
affected:
  - junos_os_evolved < 22.4
  - junos_os_evolved = 22.4
  - junos_os_evolved = 23.2
  - junos_os_evolved = 23.4
  - junos_os_evolved = 24.2
  - junos_os_evolved = 24.4
  - junos_os_evolved = 22.2
patched:
  - junos_os_evolved 22.4
published: '2026-04-09'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59969'
references:
  - url: 'https://kb.juniper.net/JSA103159'
    label: sirt@juniper.net
tags:
  - nvd
epss: 0.0018
epssPercentile: 0.06796
ingestedAt: '2026-09-30T22:27:27.751Z'
---

## Overview

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on PTX Series or QFX5000 Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).An attacker sending crafted multicast packets will cause line cards running evo-aftmand/evo-pfemand to crash and restart or non-line card devices to crash and restart. Continued receipt and processing of these packets will sustain the Denial of Service (DoS) condition.

This issue affects Junos OS Evolved PTX Series:



  *  All versions before 22.4R3-S8-EVO,
  *  from 23.2 before 23.2R2-S5-EVO,
  *  from 23.4 before 23.4R2-EVO,
  *  from 24.2 before 24.2R2-EVO,
  *  from 24.4 before 24.4R2-EVO.




This issue affects Junos OS Evolved on QFX5000 Series:



  *  22.2-EVO version before 22.2R3-S7-EVO,
  *  22.4-EVO version before 22.4R3-S7-EVO,
  *  23.2-EVO versions before 23.2R2-S4-EVO,
  *  23.4-EVO versions before 23.4R2-S5-EVO, 
  *  24.2-EVO versions before 24.2R2-S1-EVO,
  *  24.4-EVO versions before 24.4R1-S3-EVO, 24.4R2-EVO.


This issue does not affect Junos OS Evolved on QFX5000 Series versions before: 21.2R2-S1-EVO, 21.2R3-EVO, 21.3R2-EVO, 21.4R1-EVO, and 22.1R1-EVO.

## Affected

- `junos_os_evolved < 22.4`
- `junos_os_evolved = 22.4`
- `junos_os_evolved = 23.2`
- `junos_os_evolved = 23.4`
- `junos_os_evolved = 24.2`
- `junos_os_evolved = 24.4`
- `junos_os_evolved = 22.2`

## Remediation

Upgrade past the affected range:

- `junos_os_evolved 22.4`
