CVE-2026-33783 Details
Description
A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low privileges to cause a complete Denial of Service (DoS). If colored SRTE policy tunnels are provisioned via PCEP, and gRPC is used to monitor traffic in these tunnels, evo-aftmand crashes and doesn't restart which leads to a complete and persistent service impact. The system has to be manually restarted to recover. The issue is seen only when the Originator ASN field in PCEP contains a value larger than 65,535 (32-bit ASN). The issue is not reproducible when SRTE policy tunnels are statically configured. This issue affects Junos OS Evolved on PTX Series: * all versions before 22.4R3-S9-EVO, * 23.2 versions before 23.2R2-S6-EVO, * 23.4 versions before 23.4R2-S7-EVO, * 24.2 versions before 24.2R2-S4-EVO, * 24.4 versions before 24.4R2-S2-EVO, * 25.2 versions before 25.2R1-S2-EVO, 25.2R2-EVO.
A vulnerability allowing denial-of-service (DoS) has been identified in Juniper Networks Junos OS Evolved on PTX Series. This issue arises from a function call with an incorrect argument type in the sensor interface, allowing a network-based, authenticated attacker with low privileges to cause a complete service disruption. The problem occurs when colored Segment Routing Traffic Engineering (SRTE) policy tunnels are provisioned via the Path Computation Element Protocol (PCEP), and gRPC is used to monitor traffic in these tunnels. Under these conditions, the 'evo-aftmand' process crashes and does not restart, leading to a persistent service impact that requires a manual system restart to recover. The vulnerability is triggered when the Originator ASN field in PCEP contains a value larger than 65,535 (32-bit ASN) and does not occur with statically configured SRTE policy tunnels.
Users can update to Junos OS Evolved versions 22.4R3-S9-EVO, 23.2R2-S6-EVO, 23.4R2-S7-EVO, 24.2R2-S4-EVO, 24.4R2-S2-EVO, 25.2R1-S2-EVO, 25.2R2-EVO, or 25.4R1-EVO. If an immediate update is not possible, as a temporary workaround, configure the Originator ASN with a value of less than 65,535 (16-bit ASN).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA107870 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-686 | Function Call With Incorrect Argument Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos os evolved | < 22.4 22.4 - 22.4 r1 22.4 r1-s1 22.4 r1-s2 22.4 r2 22.4 r2-s1 22.4 r2-s2 22.4 r3 22.4 r3-s1 22.4 r3-s2 22.4 r3-s3 22.4 r3-s4 22.4 r3-s5 22.4 r3-s6 22.4 r3-s7 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.2 r2-s5 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 23.4 r2-s6 24.2 - 24.2 r1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 24.2 r2-s3 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 24.4 r2 24.4 r2-s1 25.2 - 25.2 r1 25.2 r1-s1 25.2 r2 |
CPE
Remediation
| |
| juniper ptx10001-36mr | All versions |
CPE
Remediation
| |
| juniper ptx10002-36qdd | All versions |
CPE
Remediation
| |
| juniper ptx10003 | All versions |
CPE
Remediation
| |
| juniper ptx10004 | All versions |
CPE
Remediation
| |
| juniper ptx10008 | All versions |
CPE
Remediation
| |
| juniper ptx10016 | All versions |
CPE
Remediation
| |
| juniper ptx12008 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 17, 2026 | Initial Analysis | [email protected] |
| Apr 9, 2026 | New CVE Received | [email protected] |