CRITICAL🇵🇱 Wersja polska

CVE-2026-21902

CVSS 9.3v4.0pub. 2026-02-25upd. 2026-03-30

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required. This issue affects Junos OS Evolved on PTX Series: * 25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO. This issue does not affect Junos OS Evolved versions before 25.4R1-EVO. This issue does not affect Junos OS.

🤖 AI Analysis
How it works

The On-Box Anomaly Detection service should be accessible only to internal system processes through an internal routing instance. In vulnerable software versions, however, this service is exposed on an externally accessible network port, allowing unauthorized network access. Attackers can contact this service directly, manipulate it, and consequently execute arbitrary code with root privileges on the device. The error results from incorrect permission assignment to a critical resource (CWE-732).

Impact

Attackers gain full control of the device with root privileges, enabling configuration reading and modification, malicious software installation, device disruption, or use as a network entry point.

Mitigation & patch

Update Junos OS Evolved to version 25.4R1-S1-EVO or 25.4R2-EVO. Until the patch is deployed, it is recommended to restrict network access to PTX series devices using firewalls or ACLs to prevent external hosts from communicating with the vulnerable service. Details available in producer bulletin JSA107128.

Who is affected

Juniper Junos OS Evolved version 25.4R1-EVO and 25.4 before 25.4R1-S1-EVO and 25.4R2-EVO running on PTX series devices: PTX10001-36MR, PTX10002-36QDD, PTX10003, PTX10004. The issue does not affect Junos OS Evolved versions earlier than 25.4R1-EVO or Junos OS systems.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:Red
  • Juniper Junos Os Evolved

    OS
    Juniper
    25.4
  • Juniper Ptx10001 36mr

    HW
    Juniper
    all versions
  • Juniper Ptx10002 36qdd

    HW
    Juniper
    all versions
  • Juniper Ptx10003

    HW
    Juniper
    all versions
  • Juniper Ptx10004

    HW
    Juniper
    all versions
  • Juniper Ptx10008

    HW
    Juniper
    all versions
  • Juniper Ptx10016

    HW
    Juniper
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-0211CRITICAL10.0PL ✓same product

Juniper Junos RPD: DoS przez nieprawidłowy BGP FlowSpec message

CVE-2026-33794HIGH8.2PL ✓same product

DoS w Juniper Junos OS Evolved – awaria procesu evo-aftmand przy unilist ECMP

CVE-2026-33801HIGH7.1PL ✓same product

DoS w RPD Juniper Junos OS przez złośliwą aktualizację BGP

CVE-2025-59969HIGH7.1same product

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forward...

CVE-2026-21919HIGH7.1same product

An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Jun...