CVE-2009-2055
בינונית 5.9 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
מדדים
- CVSS 3.1
-
5.9 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-20
מוצרים מושפעים
cisco: ios xr
קישורים
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f… PatchVendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f… PatchVendor Advisory
- http://mailman.nanog.org/pipermail/nanog/2009-August/012719.html Mailing List
- http://securitytracker.com/id?1022739 Broken Link
- http://mailman.nanog.org/pipermail/nanog/2009-August/012719.html Mailing List
- http://securitytracker.com/id?1022739 Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-200… US Government Resource