CVE-2009-1154
published 2009-08-21CVE-2009-1154: Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message…
PriorityP48low3.3CVSS 2.0
AVNACLAuMCNINAP
EPSS
1.34%
68.3th percentile
Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | <= 3.8.1 | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv2.03.3LOWAV:N/AC:L/Au:M/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
vendor_cisco·2009-08-18·CVSS 4.3
CVE-2009-1154 [MEDIUM] CWE-399 Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
Cisco IOS XR Software contains multiple vulnerabilities in the Border
Gateway Protocol (BGP) feature. These vulnerabilities include:
Cisco IOS XR Software will reset a BGP peering session when receiving
a specific invalid BGP update.
The vulnerability manifests when a BGP peer announces a prefix with a
specific invalid attribute. On receipt of this prefix, the Cisco IOS XR device
will restart the peering session by sending a notification. The peering session
will flap until the sender stops sending the invalid/corrupt update. This
vulnerability was disclosed in revision 1.0 of this advisory.
Cisco IOS XR BGP process will crash when sending a long length BGP
update message
When Cisco IOS XR sends a long length BGP update m
Cisco
Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
vendor_cisco
CVE-2009-1154 Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
CVE-2009-1154: Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
Cisco IOS XR Software contains multiple vulnerabilities in the Border Gateway Protocol (BGP) feature. These vulnerabilities include: Cisco IOS XR Software will reset a BGP peering session when receiving a specific invalid BGP update. The vulnerability manifests when a BGP peer announces a prefix with a specific invalid attribute. On receipt of this prefix, the Cisco IOS XR device will restart the peering session by sending a notification. The peering session will flap until the sender stops sending the invalid/corrupt update. This vulnerability was disclosed in revision 1.0 of this advisory. Cisco IOS XR BGP process will crash when sending a long length BGP update message When Cisco IOS XR sends a long length BGP
GHSA
GHSA-6qm4-24f4-g249: Cisco IOS XR 3
ghsa_unreviewed·2022-05-02
CVE-2009-1154 [LOW] CWE-119 GHSA-6qm4-24f4-g249: Cisco IOS XR 3
Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2009-08-21
Published