Description
A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS).

A local high-privileged user configuring or deactivating a specific 'system services ssh' configuration parameter can exploit a null pointer dereference in one of the functions used by SSH. The function attempts to dereference a null pointer when accessing certain configuration data, resulting in an mgd process crash and restart. Continued execution of these configuration commands will create a sustained Denial of Service (DoS) condition.

This issue affects:
Junos OS:


* from 22.3 before 22.3R3-S5;
* from 22.4 before 22.4R3-S10;
* from 23.2 before 23.2R2-S7;
* from 23.4 before 23.4R2-S8.




This issue does not affect Junos OS before 22.3R1.



Junos OS Evolved:
* from 22.3R1-EVO before 23.2R2-S7-EVO;
* from 23.4 before 23.4R2-S8-EVO.


This issue does not affect Junos OS Evolved before 22.3R1-EVO.
Published: 2026-07-09
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A null pointer dereference in the Juniper management daemon (mgd) is triggered when a local user with high‑privileged access configures or disables a specific SSH configuration parameter. The function attempts to dereference a null pointer, causing mgd to crash and restart. Repeated execution of these configuration commands results in a sustained Denial of Service that interrupts routing, switching, and management operations.

Affected Systems

Juniper Networks Junos OS and Junos OS Evolved are impacted. For Junos OS, all releases starting with 22.3 through 23.4 that precede 22.3R3‑S5, 22.4R3‑S10, 23.2R2‑S7, and 23.4R2‑S8 are vulnerable; earlier releases before 22.3R1 are not. For Junos OS Evolved, all releases starting with 22.3R1‑EVO through 23.4 that precede 23.2R2‑S7‑EVO and 23.4R2‑S8‑EVO are vulnerable; releases before 22.3R1‑EVO are not.

Risk and Exploitability

The CVSS score of 6.7 indicates medium severity, and the EPSS score of less than 1 % suggests low but non‑zero exploitation probability. The issue is not listed in KEV and the attack surface is confined to devices where a privileged user can log in. An attacker who controls the CLI can repeatedly apply the vulnerable configuration to keep mgd down, causing sustained service outages.

Generated by OpenCVE AI on July 28, 2026 at 08:41 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 22.3R3-S5, 22.4R3-S10, 23.2R2-S7, 23.4R2-S8, 24.2R1, and all subsequent releases. Junos OS Evolved: 23.2R2-S7-EVO, 23.4R2-S8-EVO, 24.2R1-EVO, and all subsequent releases.


Vendor Workaround

There are no direct workarounds for this issue. One of the following mitigations will prevent malicious exploitation: * Use access lists or firewall filters to limit access to the CLI only from trusted hosts and administrators. * Utilize command authorization to limit the ability to enter config mode to trusted administrators.


OpenCVE Recommended Actions

  • Upgrade the device to any of the patched releases listed in the official solution for Junos OS or Junos OS Evolved.
  • Apply access lists or firewall filters to restrict CLI access to trusted hosts.
  • Use command authorization to limit the ability to enter config mode to trusted administrators.

Generated by OpenCVE AI on July 28, 2026 at 08:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Juniper Networks junos Os Evolved
Vendors & Products Juniper Networks
Juniper Networks junos Os
Juniper Networks junos Os Evolved

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS). A local high-privileged user configuring or deactivating a specific 'system services ssh' configuration parameter can exploit a null pointer dereference in one of the functions used by SSH. The function attempts to dereference a null pointer when accessing certain configuration data, resulting in an mgd process crash and restart. Continued execution of these configuration commands will create a sustained Denial of Service (DoS) condition. This issue affects: Junos OS: * from 22.3 before 22.3R3-S5; * from 22.4 before 22.4R3-S10; * from 23.2 before 23.2R2-S7; * from 23.4 before 23.4R2-S8. This issue does not affect Junos OS before 22.3R1. Junos OS Evolved: * from 22.3R1-EVO before 23.2R2-S7-EVO; * from 23.4 before 23.4R2-S8-EVO. This issue does not affect Junos OS Evolved before 22.3R1-EVO.
Title Junos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crash
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/AU:Y/R:A/V:D/RE:M/U:Green'}


Subscriptions

Juniper Networks Junos Os Junos Os Evolved
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:21:31.624Z

Reserved: 2026-01-05T17:32:48.709Z

Link: CVE-2026-21901

cve-icon Vulnrichment

Updated: 2026-07-10T14:21:20.893Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:45:04Z

Weaknesses