CVE-2010-3035
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 6% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
cisco: ios xr
קישורים
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f… Broken LinkVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61443 VDB EntryVendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f… Broken LinkVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61443 VDB EntryVendor Advisory
- http://mailman.nanog.org/pipermail/nanog/2010-August/024837.html Mailing List
- http://osvdb.org/67696 Broken Link
- http://secunia.com/advisories/41190 Broken Link
- http://www.securitytracker.com/id?1024371 Broken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2010/2227 Broken Link
- http://mailman.nanog.org/pipermail/nanog/2010-August/024837.html Mailing List