cbcvebase.
CVE-2010-3035
published 2010-08-30

CVE-2010-3035: Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a…

PriorityP272high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
5.56%
92.0th percentile
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscoios_xr
ciscoios_xr3.4.0 – 3.9.1

Detection & IOCsextracted from sources · hover to see the quote

otherBGP attribute type code 99
  • Detect BGP UPDATE messages carrying unrecognized transitive attribute type code 99, which is the specific attribute observed in the wild exploitation of this vulnerability.
  • Monitor for BGP peering session resets following receipt of a prefix announcement with an unrecognized transitive attribute — the IOS XR device corrupts the attribute before forwarding, causing downstream peers to reset.
  • Cisco IOS (non-XR) devices are also affected as victims: they will reset a BGP session upon receipt of the corrupted/malformed update forwarded by an IOS XR device, so session resets on IOS peers can be an indirect indicator.
  • ·Vulnerability is only present when BGP is enabled on Cisco IOS XR 3.4.0 through 3.9.1. Devices without BGP configured are not affected.
  • ·The corrupted attribute is forwarded to neighboring devices, meaning non-IOS XR peers (including third-party BGP implementations) may also reset their sessions — the blast radius extends beyond the directly vulnerable device.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.