A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS).
A local high-privileged user configuring or deactivating a specific 'system services ssh' configuration parameter can exploit a null pointer dereference in one of the functions used by SSH. The function attempts to dereference a null pointer when accessing certain configuration data, resulting in an mgd process crash and restart. Continued execution of these configuration commands will create a sustained Denial of Service (DoS) condition.
This issue affects:
Junos OS:
* from 22.3 before 22.3R3-S5;
* from 22.4 before 22.4R3-S10;
* from 23.2 before 23.2R2-S7;
* from 23.4 before 23.4R2-S8.
This issue does not affect Junos OS before 22.3R1.
Junos OS Evolved:
* from 22.3R1-EVO before 23.2R2-S7-EVO;
* from 23.4 before 23.4R2-S8-EVO.
This issue does not affect Junos OS Evolved before 22.3R1-EVO.
References
| Link | Resource |
|---|---|
| https://github.com/orangecertcc/security-research/security/advisories/GHSA-g4f7-w2rc-hpj6 | Mitigation Exploit Third Party Advisory |
| https://supportportal.juniper.net/JSA110072 | Vendor Advisory |
| https://github.com/orangecertcc/security-research/security/advisories/GHSA-g4f7-w2rc-hpj6 | Mitigation Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
History
No history.
Information
Published : 2026-07-09 21:16
Updated : 2026-08-26 17:48
NVD link : CVE-2026-21901
Mitre link : CVE-2026-21901
CVE.ORG link : CVE-2026-21901
JSON object : View
Products Affected
juniper
- junos_os_evolved
- junos
CWE
CWE-476
NULL Pointer Dereference
