CVE-2009-2055
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
Attend
*SSVC
Descriptions
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
Cisco IOS XR desde la v3.4.0 hasta la v3.8.1 permite a atacantes remotos producir una denegación de servicio (reset de sesión) a través de el mensaje BGP UPDATE con un atributo invalido, como se demostró el 17 de Agosto de 2009.
Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-06-12 CVE Reserved
- 2009-08-18 CVE Published
- 2022-03-25 Exploited in Wild
- 2022-04-15 KEV Due Date
- 2024-09-17 EPSS Updated
- 2024-11-15 CVE Updated
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://mailman.nanog.org/pipermail/nanog/2009-August/012719.html | Mailing List | |
http://securitytracker.com/id?1022739 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml | 2009-08-21 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.4 Search vendor "Cisco" for product "Ios Xr" and version "3.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.4.0 Search vendor "Cisco" for product "Ios Xr" and version "3.4.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.4.1 Search vendor "Cisco" for product "Ios Xr" and version "3.4.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.4.2 Search vendor "Cisco" for product "Ios Xr" and version "3.4.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.4.3 Search vendor "Cisco" for product "Ios Xr" and version "3.4.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.5 Search vendor "Cisco" for product "Ios Xr" and version "3.5" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.5.2 Search vendor "Cisco" for product "Ios Xr" and version "3.5.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.5.3 Search vendor "Cisco" for product "Ios Xr" and version "3.5.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.5.4 Search vendor "Cisco" for product "Ios Xr" and version "3.5.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.6.0 Search vendor "Cisco" for product "Ios Xr" and version "3.6.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.6.1 Search vendor "Cisco" for product "Ios Xr" and version "3.6.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.6.2 Search vendor "Cisco" for product "Ios Xr" and version "3.6.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.6.3 Search vendor "Cisco" for product "Ios Xr" and version "3.6.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.7.0 Search vendor "Cisco" for product "Ios Xr" and version "3.7.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.7.1 Search vendor "Cisco" for product "Ios Xr" and version "3.7.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.7.2 Search vendor "Cisco" for product "Ios Xr" and version "3.7.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.7.3 Search vendor "Cisco" for product "Ios Xr" and version "3.7.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.8.0 Search vendor "Cisco" for product "Ios Xr" and version "3.8.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ios Xr Search vendor "Cisco" for product "Ios Xr" | 3.8.1 Search vendor "Cisco" for product "Ios Xr" and version "3.8.1" | - |
Affected
|