Junglewise Threat Intelligence

CVE-2010-3035: Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

CVE-2010-3035 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-25

Technologies: Cisco IOS XR. Vendors: Cisco.

Executive brief

Cisco IOS XR software fails to properly handle unrecognized transitive BGP attributes. A remote attacker can trigger a denial-of-service condition (peering reset) by sending a crafted prefix announcement containing specific attribute type codes, such as type code 99.

Affected products

  • Cisco IOS XR 3.4.0 through 3.9.1

Timeline

  • 2010-08-27: exploited: Demonstrated in the wild with attribute type code 99.
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats