Database/Firmware, BMC & network fabric
Junos mgd: null pointer dereference on an SSH configuration change crashes the management daemon
Impact
Setting or deactivating a specific 'system services ssh' configuration parameter makes mgd dereference a null pointer and crash. Repeating the command keeps mgd restarting, which is a sustained denial of service on the management plane of the device. On Junos gear carrying datacenter fabric or out-of-band management traffic, a crashed mgd does not drop forwarding, but it does block configuration changes, commits and automation for as long as the condition is driven - so an operator cannot reconfigure or roll back the device during an incident. Exposure is limited: the attacker must already hold a high-privileged configuration account on the box.
Who can reach it
A local, authenticated, high-privileged user with Junos configuration rights (CLI or NETCONF/management session). Not reachable from tenant or data-plane traffic.
What to do
Upgrade to a fixed release per Juniper JSA110072: Junos OS 22.3R3-S5, 22.4R3-S10, 23.2R2-S7, 23.4R2-S8; Junos OS Evolved 23.2R2-S7-EVO, 23.4R2-S8-EVO. Junos upgrades take the device through a reboot, so schedule a maintenance window and fail traffic to the redundant path first. Until then, restrict who holds configuration privilege on affected devices.
References
Related entries
- HPE iLO 5 (firmware update security restriction bypass): Bypass of the security restrictions that guard iLO 5 firmwareCVE-2018-7113 · HPE iLO 5 (firmware update security restriction bypass)Medium
- AMI MegaRAC SPx (BMC hard-coded credentials): Hard-coded credentials inside the BMC firmwareCVE-2023-34473 · AMI MegaRAC SPx (BMC hard-coded credentials)Medium
- Cisco FXOS / NX-OS (LLDP frame handling denial of service): An unauthenticated adjacent attacker sends crafted LLDPCVE-2024-20294 · Cisco FXOS / NX-OS (LLDP frame handling denial of service)Medium
- AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmware: The PMU firmware on Zynq UltraScale+CVE-2025-0038 · AMD Zynq UltraScale+ - CSU runtime service address validation in PMU firmwareMedium
- TCG TPM 2.0 reference implementation (CryptHmacSign): Out-of-bounds read in the reference implementation's HMAC signingCVE-2025-2884 · TCG TPM 2.0 reference implementation (CryptHmacSign)Medium
- Linux kernel (drivers/infiniband/hw/irdma): A stale flag caused the CQ memory-registration path to read one elementCVE-2026-74346 · Linux kernel (drivers/infiniband/hw/irdma)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.