cbcvebase.
CVE-2009-2055
published 2009-08-19

CVE-2009-2055: Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as…

PriorityP269medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
3.33%
87.2th percentile
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.

Affected

20 ranges
VendorProductVersion rangeFixed in
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr
ciscoios_xr

Detection & IOCsextracted from sources · hover to see the quote

  • Detect BGP UPDATE messages containing a specific invalid attribute directed at Cisco IOS XR devices; receipt of such a prefix causes the device to send a BGP NOTIFICATION and reset the peering session
  • Monitor BGP peering sessions on Cisco IOS XR for repeated session flaps (session reset loop), which is a behavioral indicator of exploitation — the session will flap until the sender stops sending the invalid/corrupt update
  • Monitor for BGP process crashes on Cisco IOS XR when the device sends or constructs unusually long BGP UPDATE messages (e.g., those with an abnormally large AS path or excessive AS prepends)
  • Track Cisco bug IDs CSCtb42995, CSCtb05382, CSCtb12726, CSCtb18562 for patch status verification on IOS XR devices; unpatched devices running IOS XR 3.4.0 through 3.8.1 with BGP configured are vulnerable

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vulncheck5.9MEDIUM
cisa5.9MEDIUM
vendor_cisco4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.