Vulnerability Description
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xr | 3.4 |
Related Weaknesses (CWE)
References
- http://mailman.nanog.org/pipermail/nanog/2009-August/012719.htmlMailing List
- http://securitytracker.com/id?1022739Broken Link
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.sPatchVendor Advisory
- http://mailman.nanog.org/pipermail/nanog/2009-August/012719.htmlMailing List
- http://securitytracker.com/id?1022739Broken Link
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.sPatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-US Government Resource
FAQ
What is CVE-2009-2055?
CVE-2009-2055 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
How severe is CVE-2009-2055?
CVE-2009-2055 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2055?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xr.