CVE-2009-2055
cisco ios xr
Published 19 Aug 2009 · updated 16 Jun 2026 · Analyzed
5.9 Medium · CVSS 3.1, CISA ADP
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 25 Mar 2022, with a remediation deadline of 15 Apr 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
References
- mailman.nanog.org/pipermail/nanog/2009-August/012719.html · Mailing List
- securitytracker.com/id?1022739 · Broken Link
- www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml · Patch, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-2055 · US Government Resource