Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33783

22
FAUCET Score

OVERVIEW CVE-2026-33783 is a function call argument type vulnerability in Juniper Networks Junos OS Evolved affecting PTX Series routers. When colored Segment Routing Traffic Engineering (SRTE) policy tunnels are provisioned via Path Computation Element Communication Protocol (PCEP) with gRPC traffic monitoring enabled, an incorrect argument type causes the evo-aftmand process to crash if the PCEP Originator ASN field contains a 32-bit ASN value exceeding 65,535. The vulnerability affects multiple software versions ranging from 22.4 through 25.2, with static tunnel configurations remaining unaffected. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) with a network-based attack vector requiring low-privilege authenticated access and no user interaction. The primary impact is availability, resulting in complete denial of service as the crashed process does not automatically restart and requires manual system reboot for recovery. This constitutes a persistent service disruption that could affect router operations in production networks, though exploitation requires specific network configuration conditions and legitimate system access. EXPLOITATION STATUS CVE-2026-33783 shows no evidence of active exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, maintains an inactive Hot List status, and demonstrates an extremely low EPSS score of 0.0005, indicating negligible community exploitation activity. No public exploit code is currently available, and the restrictive exploitation requirements—authentication, specific tunnel configurations, and particular ASN values—further limit real-world attack feasibility.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 22.4R3-S9-EVOCPE match
cpe:2.3:o:juniper:junos_os_evolved:*:r1:*:*:*:*:*:*
>= 23.2, < 23.2R2-S6-EVOCPE match
cpe:2.3:o:juniper:junos_os_evolved:*:r1:*:*:*:*:*:*
>= 23.4, < 23.4R2-S7-EVOCPE match
cpe:2.3:o:juniper:junos_os_evolved:*:r1:*:*:*:*:*:*
>= 24.2, < 24.2R2-S4-EVOCPE match
cpe:2.3:o:juniper:junos_os_evolved:*:r1:*:*:*:*:*:*
>= 24.4, < 24.4R2-S2-EVOCPE match
cpe:2.3:o:juniper:junos_os_evolved:*:r1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.1HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 17th percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

junipervendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

juniperjuniper:ka0Dp000000vDu5IAE

2026-04 Security Bulletin: Junos OS Evolved: PTX Series: If SRTE tunnels provisioned via PCEP are present and specific gRPC queries are received evo-aftmand crashes (CVE-2026-33783)

Apr 9, 2026
juniperjuniper:ka0Dp000000vCeLIAU

2026-04 Security Bulletin: Junos OS Evolved: PTX Series: If SRTE tunnels provisioned via PCEP are present and specific gRPC queries are received evo-aftman crashes (CVE-2026-33783)

Apr 8, 2026

References

kb.juniper.net / JSA107870
MitigationVendor Advisory