Junglewise Threat Intelligence

CVE-2009-2055: Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

CVE-2009-2055 · Severity: critical · CVSS 5.9 · Exploited in the wild · Published 2022-03-25

Technologies: Cisco IOS XR. Vendors: Cisco.

Executive brief

Cisco IOS XR allows remote attackers to cause a denial of service (BGP session reset) via a BGP UPDATE message containing an invalid attribute. This vulnerability specifically impacts systems where BGP is the configured routing feature.

Affected products

  • Cisco IOS XR 3.4.0 through 3.8.1

Timeline

  • 2009-08-17: exploited: Demonstrated in the wild.
  • 2009-08-19: disclosed: NVD Published Date.
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats