CVE-2010-3035
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 5.56% probability · 92th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Affected
- cisco/ios xr
- Source
- psirt@cisco.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-3035
References
- http://mailman.nanog.org/pipermail/nanog/2010-August/024837.htmlMailing List
- http://osvdb.org/67696Broken Link
- http://secunia.com/advisories/41190Broken Link
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtmlBroken Link, Vendor Advisory
- http://www.securitytracker.com/id?1024371Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/2227Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61443VDB Entry, Vendor Advisory
- http://mailman.nanog.org/pipermail/nanog/2010-August/024837.htmlMailing List
- http://osvdb.org/67696Broken Link
- http://secunia.com/advisories/41190Broken Link
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtmlBroken Link, Vendor Advisory
- http://www.securitytracker.com/id?1024371Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/2227Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61443VDB Entry, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3035US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.