PT-2026-56924 · Juniper Networks · Junos Evolved+1

·

CVE-2026-21901

·

Published

2026-07-08

·

Updated

2026-07-10

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Junos OS versions 22.3 through 22.3R3-S5 Junos OS versions 22.4 through 22.4R3-S10 Junos OS versions 23.2 through 23.2R2-S7 Junos OS versions 23.4 through 23.4R2-S8 Junos OS Evolved versions 22.3R1-EVO through 23.2R2-S7-EVO Junos OS Evolved versions 23.4 through 23.4R2-S8-EVO
Description A NULL Pointer Dereference in the management daemon (mgd) allows a local, high-privileged attacker to cause a Denial of Service (DoS). By configuring or deactivating a specific system services ssh configuration parameter, the attacker can trigger a crash and restart of the mgd process. A NULL Pointer Dereference occurs when a program attempts to read or write to a memory address that is NULL, which typically leads to an application crash. Repeated execution of these commands can result in a sustained DoS condition.
Recommendations Update Junos OS to version 22.3R3-S5 or later. Update Junos OS to version 22.4R3-S10 or later. Update Junos OS to version 23.2R2-S7 or later. Update Junos OS to version 23.4R2-S8 or later. Update Junos OS Evolved to version 23.2R2-S7-EVO or later. Update Junos OS Evolved to version 23.4R2-S8-EVO or later. As a temporary mitigation, restrict high-privileged access to the system services ssh configuration parameter.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09567
CVE-2026-21901

Affected Products

Junos
Junos Evolved