CVE-2010-3035
published 2010-08-30CVE-2010-3035: Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a…
PriorityP272high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
5.56%
92.0th percentile
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | 3.4.0 – 3.9.1 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect BGP UPDATE messages carrying unrecognized transitive attribute type code 99, which is the specific attribute observed in the wild exploitation of this vulnerability. ↗
- →Monitor for BGP peering session resets following receipt of a prefix announcement with an unrecognized transitive attribute — the IOS XR device corrupts the attribute before forwarding, causing downstream peers to reset. ↗
- →Cisco IOS (non-XR) devices are also affected as victims: they will reset a BGP session upon receipt of the corrupted/malformed update forwarded by an IOS XR device, so session resets on IOS peers can be an indirect indicator. ↗
- ·Vulnerability is only present when BGP is enabled on Cisco IOS XR 3.4.0 through 3.9.1. Devices without BGP configured are not affected. ↗
- ·The corrupted attribute is forwarded to neighboring devices, meaning non-IOS XR peers (including third-party BGP implementations) may also reset their sessions — the blast radius extends beyond the directly vulnerable device. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
cisa·2022-03-25·CVSS 7.5
CVE-2010-3035 [HIGH] CWE-20 Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Vulnerability: Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Affected: Cisco IOS XR
Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-3035
Remediation Due Date: 2022-04-15
Cisco
Cisco IOS XR Software Border Gateway Protocol Vulnerability
vendor_cisco·2010-08-28·CVSS 5.0
CVE-2010-3035 [MEDIUM] CWE-399 Cisco IOS XR Software Border Gateway Protocol Vulnerability
Cisco IOS XR Software Border Gateway Protocol Vulnerability
Cisco IOS XR Software contains a vulnerability in the Border Gateway
Protocol (BGP) feature. The vulnerability manifests itself when a BGP peer
announces a prefix with a specific, valid but unrecognized transitive
attribute. On receipt of this prefix, the Cisco IOS XR device will corrupt the
attribute before sending it to the neighboring devices. Neighboring devices
that receive this corrupted update may reset the BGP peering session.
Affected devices running Cisco IOS XR Software corrupt the
unrecognized attribute before sending to neighboring devices, but neighboring
devices may be running operating systems other than Cisco IOS XR Software and
may still reset the BGP peering session after receiving the corrupted update.
This is
Cisco
Cisco IOS XR Software Border Gateway Protocol Vulnerability
vendor_cisco
CVE-2010-3035 Cisco IOS XR Software Border Gateway Protocol Vulnerability
CVE-2010-3035: Cisco IOS XR Software Border Gateway Protocol Vulnerability
Cisco IOS XR Software contains a vulnerability in the Border Gateway Protocol (BGP) feature. The vulnerability manifests itself when a BGP peer announces a prefix with a specific, valid but unrecognized transitive attribute. On receipt of this prefix, the Cisco IOS XR device will corrupt the attribute before sending it to the neighboring devices. Neighboring devices that receive this corrupted update may reset the BGP peering session. Affected devices running Cisco IOS XR Software corrupt the unrecognized attribute before sending to neighboring devices, but neighboring devices may be running operating systems other than Cisco IOS XR Software and may still reset the BGP peering session after receiving the corrupted u
GHSA
GHSA-9q29-g37m-5wmp: Cisco IOS XR 3
ghsa_unreviewed·2022-05-17
CVE-2010-3035 [MEDIUM] CWE-20 GHSA-9q29-g37m-5wmp: Cisco IOS XR 3
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
VulnCheck
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
vulncheck·2010·CVSS 7.5
CVE-2010-3035 [HIGH] CWE-20 Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
Affected: Cisco IOS XR
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-04-15
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://mailman.nanog.org/pipermail/nanog/2010-August/024837.htmlhttp://osvdb.org/67696http://secunia.com/advisories/41190http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtmlhttp://www.securitytracker.com/id?1024371http://www.vupen.com/english/advisories/2010/2227https://exchange.xforce.ibmcloud.com/vulnerabilities/61443http://mailman.nanog.org/pipermail/nanog/2010-August/024837.htmlhttp://osvdb.org/67696http://secunia.com/advisories/41190http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtmlhttp://www.securitytracker.com/id?1024371http://www.vupen.com/english/advisories/2010/2227https://exchange.xforce.ibmcloud.com/vulnerabilities/61443https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3035
2010-08-30
Published
2022-03-25
Added to CISA KEV
Exploited in the wild