3.3
CVSSv2

CVE-2009-1154

Published: 21/08/2009 Updated: 21/08/2009
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.4
VMScore: 294
Vector: AV:N/AC:L/Au:M/C:N/I:N/A:P

Vulnerability Summary

Cisco IOS XR 3.8.1 and previous versions allows remote malicious users to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xr 3.5

cisco ios xr 3.5.3

cisco ios xr 3.5.2

cisco ios xr 3.5.4

cisco ios xr 3.6.0

cisco ios xr 3.4.0

cisco ios xr 3.4.2

cisco ios xr 3.6.2

cisco ios xr 3.7.0

cisco ios xr 3.4

cisco ios xr 3.7.2

cisco ios xr 3.7.3

cisco ios xr 3.8.0

cisco ios xr

cisco ios xr 3.4.1

cisco ios xr 3.4.3

cisco ios xr 3.6.3

cisco ios xr 3.7.1

cisco ios xr 3.6.1

Vendor Advisories

Cisco IOS XR Software contains multiple vulnerabilities in the Border Gateway Protocol (BGP) feature These vulnerabilities include: Cisco IOS XR Software will reset a BGP peering session when receiving a specific invalid BGP update The vulnerability manifests when a BGP peer announces a prefix with a specific invalid attribute ...