Impact
A null pointer dereference in the Juniper management daemon (mgd) is triggered when a local user with high‑privileged access configures or disables a specific SSH configuration parameter. The function attempts to dereference a null pointer, causing mgd to crash and restart. Repeated execution of these configuration commands results in a sustained Denial of Service that interrupts routing, switching, and management operations.
Affected Systems
Juniper Networks Junos OS and Junos OS Evolved are impacted. For Junos OS, all releases starting with 22.3 through 23.4 that precede 22.3R3‑S5, 22.4R3‑S10, 23.2R2‑S7, and 23.4R2‑S8 are vulnerable; earlier releases before 22.3R1 are not. For Junos OS Evolved, all releases starting with 22.3R1‑EVO through 23.4 that precede 23.2R2‑S7‑EVO and 23.4R2‑S8‑EVO are vulnerable; releases before 22.3R1‑EVO are not.
Risk and Exploitability
The CVSS score of 6.7 indicates medium severity, and the EPSS score of less than 1 % suggests low but non‑zero exploitation probability. The issue is not listed in KEV and the attack surface is confined to devices where a privileged user can log in. An attacker who controls the CLI can repeatedly apply the vulnerable configuration to keep mgd down, causing sustained service outages.
OpenCVE Enrichment