CVE-2009-2055
published 2009-08-19CVE-2009-2055: Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as…
PriorityP269medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
3.33%
87.2th percentile
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect BGP UPDATE messages containing a specific invalid attribute directed at Cisco IOS XR devices; receipt of such a prefix causes the device to send a BGP NOTIFICATION and reset the peering session ↗
- →Monitor BGP peering sessions on Cisco IOS XR for repeated session flaps (session reset loop), which is a behavioral indicator of exploitation — the session will flap until the sender stops sending the invalid/corrupt update ↗
- →Monitor for BGP process crashes on Cisco IOS XR when the device sends or constructs unusually long BGP UPDATE messages (e.g., those with an abnormally large AS path or excessive AS prepends) ↗
- →Track Cisco bug IDs CSCtb42995, CSCtb05382, CSCtb12726, CSCtb18562 for patch status verification on IOS XR devices; unpatched devices running IOS XR 3.4.0 through 3.8.1 with BGP configured are vulnerable ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vulncheck5.9MEDIUM
cisa5.9MEDIUM
vendor_cisco4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
cisa·2022-03-25·CVSS 5.9
CVE-2009-2055 [MEDIUM] CWE-20 Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Vulnerability: Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Affected: Cisco IOS XR
Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2009-2055
Remediation Due Date: 2022-04-15
Cisco
Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
vendor_cisco·2009-08-18·CVSS 4.3
CVE-2009-1154 [MEDIUM] CWE-399 Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
Cisco IOS XR Software contains multiple vulnerabilities in the Border
Gateway Protocol (BGP) feature. These vulnerabilities include:
Cisco IOS XR Software will reset a BGP peering session when receiving
a specific invalid BGP update.
The vulnerability manifests when a BGP peer announces a prefix with a
specific invalid attribute. On receipt of this prefix, the Cisco IOS XR device
will restart the peering session by sending a notification. The peering session
will flap until the sender stops sending the invalid/corrupt update. This
vulnerability was disclosed in revision 1.0 of this advisory.
Cisco IOS XR BGP process will crash when sending a long length BGP
update message
When Cisco IOS XR sends a long length BGP update m
Cisco
Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
vendor_cisco
CVE-2009-2055 Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
CVE-2009-2055: Cisco IOS XR Software Border Gateway Protocol Vulnerabilities
Cisco IOS XR Software contains multiple vulnerabilities in the Border Gateway Protocol (BGP) feature. These vulnerabilities include: Cisco IOS XR Software will reset a BGP peering session when receiving a specific invalid BGP update. The vulnerability manifests when a BGP peer announces a prefix with a specific invalid attribute. On receipt of this prefix, the Cisco IOS XR device will restart the peering session by sending a notification. The peering session will flap until the sender stops sending the invalid/corrupt update. This vulnerability was disclosed in revision 1.0 of this advisory. Cisco IOS XR BGP process will crash when sending a long length BGP update message When Cisco IOS XR sends a long length BGP
GHSA
GHSA-2j56-f322-jxrm: Cisco IOS XR 3
ghsa_unreviewed·2022-05-02
CVE-2009-2055 [MEDIUM] CWE-20 GHSA-2j56-f322-jxrm: Cisco IOS XR 3
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
VulnCheck
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
vulncheck·2009·CVSS 5.9
CVE-2009-2055 [MEDIUM] CWE-20 Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
Affected: Cisco IOS XR
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-04-15
No detection rules found.
No public exploits indexed.
http://mailman.nanog.org/pipermail/nanog/2009-August/012719.htmlhttp://securitytracker.com/id?1022739http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtmlhttp://mailman.nanog.org/pipermail/nanog/2009-August/012719.htmlhttp://securitytracker.com/id?1022739http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-2055
2009-08-19
Published
2022-03-25
Added to CISA KEV
Exploited in the wild