Executive brief
Cisco IOS XR software fails to properly handle unrecognized transitive BGP attributes. A remote attacker can trigger a denial-of-service condition (peering reset) by sending a crafted prefix announcement containing specific attribute type codes, such as type code 99.
Affected products
- Cisco IOS XR 3.4.0 through 3.9.1
Timeline
- 2010-08-27: exploited: Demonstrated in the wild with attribute type code 99.
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.