GPU VulnDB

Database/Firmware, BMC & network fabric

Junos mgd: null pointer dereference on an SSH configuration change crashes the management daemon

CVE-2026-21901Firmware, BMC & network fabriccurated

Impact

Setting or deactivating a specific 'system services ssh' configuration parameter makes mgd dereference a null pointer and crash. Repeating the command keeps mgd restarting, which is a sustained denial of service on the management plane of the device. On Junos gear carrying datacenter fabric or out-of-band management traffic, a crashed mgd does not drop forwarding, but it does block configuration changes, commits and automation for as long as the condition is driven - so an operator cannot reconfigure or roll back the device during an incident. Exposure is limited: the attacker must already hold a high-privileged configuration account on the box.

Who can reach it

A local, authenticated, high-privileged user with Junos configuration rights (CLI or NETCONF/management session). Not reachable from tenant or data-plane traffic.

What to do

Upgrade to a fixed release per Juniper JSA110072: Junos OS 22.3R3-S5, 22.4R3-S10, 23.2R2-S7, 23.4R2-S8; Junos OS Evolved 23.2R2-S7-EVO, 23.4R2-S8-EVO. Junos upgrades take the device through a reboot, so schedule a maintenance window and fail traffic to the redundant path first. Until then, restrict who holds configuration privilege on affected devices.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.