CVE-2009-2055

cisco ios xr

Published 19 Aug 2009 · updated 16 Jun 2026 · Analyzed

5.9 Medium · CVSS 3.1, CISA ADP

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 25 Mar 2022, with a remediation deadline of 15 Apr 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.

References