Executive brief
Cisco IOS XR allows remote attackers to cause a denial of service (BGP session reset) via a BGP UPDATE message containing an invalid attribute. This vulnerability specifically impacts systems where BGP is the configured routing feature.
Affected products
- Cisco IOS XR 3.4.0 through 3.8.1
Timeline
- 2009-08-17: exploited: Demonstrated in the wild.
- 2009-08-19: disclosed: NVD Published Date.
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.