CVE-2010-3035
moderate-risk
Published 2010-08-30
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
Do I need to act?
~
3.2% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (15)
Broken Link
http://osvdb.org/67696
Broken Link
http://secunia.com/advisories/41190
Broken Link
http://www.securitytracker.com/id?1024371
Broken Link
http://osvdb.org/67696
Broken Link
http://secunia.com/advisories/41190
Broken Link
http://www.securitytracker.com/id?1024371
45
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
14/34 · Moderate
Exposure
5/34 · Minimal