PT-2026-56924 · Juniper Networks · Junos Evolved+1
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Junos OS versions 22.3 through 22.3R3-S5
Junos OS versions 22.4 through 22.4R3-S10
Junos OS versions 23.2 through 23.2R2-S7
Junos OS versions 23.4 through 23.4R2-S8
Junos OS Evolved versions 22.3R1-EVO through 23.2R2-S7-EVO
Junos OS Evolved versions 23.4 through 23.4R2-S8-EVO
Description
A NULL Pointer Dereference in the management daemon (mgd) allows a local, high-privileged attacker to cause a Denial of Service (DoS). By configuring or deactivating a specific
system services ssh configuration parameter, the attacker can trigger a crash and restart of the mgd process. A NULL Pointer Dereference occurs when a program attempts to read or write to a memory address that is NULL, which typically leads to an application crash. Repeated execution of these commands can result in a sustained DoS condition.Recommendations
Update Junos OS to version 22.3R3-S5 or later.
Update Junos OS to version 22.4R3-S10 or later.
Update Junos OS to version 23.2R2-S7 or later.
Update Junos OS to version 23.4R2-S8 or later.
Update Junos OS Evolved to version 23.2R2-S7-EVO or later.
Update Junos OS Evolved to version 23.4R2-S8-EVO or later.
As a temporary mitigation, restrict high-privileged access to the
system services ssh configuration parameter.Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Junos
Junos Evolved