{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-22T16:45:03.617","vulnerabilities":[{"cve":{"id":"CVE-2026-21902","sourceIdentifier":"sirt@juniper.net","published":"2026-02-25T18:23:40.360","lastModified":"2026-06-17T10:19:07.143","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root.\n\nThe On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device.\nPlease note that this service is enabled by default as no specific configuration is required.\n\nThis issue affects Junos OS Evolved on PTX Series:\n\n\n\n  *  25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO.\n\n\n\n\nThis issue does not affect Junos OS Evolved versions before 25.4R1-EVO.\n\nThis issue does not affect Junos OS."},{"lang":"es","value":"Una vulnerabilidad de Asignación Incorrecta de Permisos para Recursos Críticos en el framework de detección de anomalías On-Box de Juniper Networks Junos OS Evolved en la serie PTX permite a un atacante no autenticado y basado en red ejecutar código como root.\n\nEl framework de detección de anomalías On-Box solo debería ser accesible por otros procesos internos a través de la instancia de enrutamiento interna, pero no a través de un puerto expuesto externamente. Con la capacidad de acceder y manipular el servicio para ejecutar código como root, un atacante remoto puede tomar el control completo del dispositivo.\nTenga en cuenta que este servicio está habilitado por defecto ya que no se requiere ninguna configuración específica.\n\nEste problema afecta a Junos OS Evolved en la serie PTX:\n\n  *  versiones 25.4 anteriores a 25.4R1-S1-EVO, 25.4R2-EVO.\n\nEste problema no afecta a las versiones de Junos OS Evolved anteriores a 25.4R1-EVO.\n\nEste problema no afecta a Junos OS."}],"affected":[{"source":"sirt@juniper.net","affectedData":[{"vendor":"Juniper Networks","product":"Junos OS Evolved","defaultStatus":"unaffected","platforms":["PTX Series"],"versions":[{"version":"25.4","lessThan":"25.4R1-S1-EVO, 25.4R2-EVO","versionType":"semver","status":"affected"},{"version":"0","lessThan":"25.4R1-EVO","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"sirt@juniper.net","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:Red","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"YES","Recovery":"USER","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"RED"}}],"cvssMetricV31":[{"source":"sirt@juniper.net","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-25T00:00:00+00:00","id":"CVE-2026-21902","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"sirt@juniper.net","type":"Secondary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:juniper:junos_os_evolved:25.4:r1:*:*:*:*:*:*","matchCriteriaId":"21728887-97A1-4AC7-8121-B6CEA5D6BAB4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:juniper:ptx10001-36mr:-:*:*:*:*:*:*:*","matchCriteriaId":"C188428C-0558-44FB-845C-E885DE9A0733"},{"vulnerable":false,"criteria":"cpe:2.3:h:juniper:ptx10002-36qdd:-:*:*:*:*:*:*:*","matchCriteriaId":"F805FE65-289B-404D-87A3-289A4A9AC927"},{"vulnerable":false,"criteria":"cpe:2.3:h:juniper:ptx10003:-:*:*:*:*:*:*:*","matchCriteriaId":"5BD05415-9F94-4EB8-805A-C9C0FFA9D0DF"},{"vulnerable":false,"criteria":"cpe:2.3:h:juniper:ptx10004:-:*:*:*:*:*:*:*","matchCriteriaId":"C432E543-37F5-4CA0-B239-2B97C6A16907"},{"vulnerable":false,"criteria":"cpe:2.3:h:juniper:ptx10008:-:*:*:*:*:*:*:*","matchCriteriaId":"65A64A26-4606-4D33-8958-5A3B7FFC4CDB"},{"vulnerable":false,"criteria":"cpe:2.3:h:juniper:ptx10016:-:*:*:*:*:*:*:*","matchCriteriaId":"1879799F-18B2-4958-AA90-FD19348C889F"}]}]}],"references":[{"url":"https://kb.juniper.net/JSA107128","source":"sirt@juniper.net","tags":["Mitigation","Vendor Advisory"]},{"url":"https://supportportal.juniper.net/JSA107128","source":"sirt@juniper.net","tags":["Mitigation","Vendor Advisory"]},{"url":"https://github.com/watchtowrlabs/watchTowr-vs-JunosEvolved-CVE-2026-21902/blob/main/watchTowr-vs-JunosEvolved-CVE-2026-21902.py","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Product"]}]}}]}