CVE-2010-3035
cisco ios xr
Published 30 Aug 2010 · updated 16 Jun 2026 · Analyzed
7.5 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 25 Mar 2022, with a remediation deadline of 15 Apr 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
References
- mailman.nanog.org/pipermail/nanog/2010-August/024837.html · Mailing List
- osvdb.org/67696 · Broken Link
- secunia.com/advisories/41190 · Broken Link
- www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtml · Broken Link, Vendor Advisory
- www.securitytracker.com/id?1024371 · Broken Link, Third Party Advisory, VDB Entry
- www.vupen.com/english/advisories/2010/2227 · Broken Link
- exchange.xforce.ibmcloud.com/vulnerabilities/61443 · VDB Entry, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-3035 · US Government Resource