Vulnerability record · CVE-2009-2055 · published 19 August 2009
CVE-2009-2055: Cisco IOS XR BGP invalid attribute causes session reset DoS
Cisco · Ios Xr
Cisco IOS XR 3.4.0 through 3.8.1 fails to properly validate a BGP UPDATE message attribute, allowing a remote peer to reset BGP sessions. Because BGP session resets disrupt routing, this can cause a denial of service on affected routers. The flaw was demonstrated in the wild on 17 August 2009.
Description
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild demonstration and causes availability loss on core routing, though CVSS rates it medium and exploitation requires BGP reachability.
What it is
Cisco IOS XR 3.4.0 through 3.8.1 fails to properly validate a BGP UPDATE message attribute, allowing a remote peer to reset BGP sessions. Because BGP session resets disrupt routing, this can cause a denial of service on affected routers. The flaw was demonstrated in the wild on 17 August 2009.
Impact
An attacker can force BGP session resets on affected IOS XR routers, disrupting routing and causing a denial of service. No confidentiality or integrity impact is described; the effect is availability only.
Attack surface
Reached over the network via a crafted BGP UPDATE message sent to a router running an affected IOS XR version. The CVSS vector shows no privileges and no user interaction required, though attack complexity is rated high, consistent with needing a BGP peering relationship or the ability to inject BGP traffic.
Exploitation
CVE-2009-2055 is listed in CISA KEV with a due date of 2022-04-15, and the description states it was demonstrated in the wild in 2009. EPSS 30-day probability is about 3.3 percent (87.9th percentile), and no ransomware campaign use is recorded.
What to do
- Apply the Cisco vendor advisory updates for IOS XR 3.4.0 through 3.8.1 as the primary fix.
- Restrict BGP peering to trusted, authenticated neighbors and apply prefix and attribute filtering where feasible.
- Monitor BGP session stability and alert on repeated resets from the same peer.
- If patching cannot be done immediately, isolate or rate-limit untrusted BGP sources per network design.
Detection
- Alert on repeated BGP session resets or flaps on IOS XR routers, especially correlated with a single peer.
- Log and review BGP UPDATE messages containing malformed or unexpected attributes.
- Track IOS XR version inventory to identify devices still running 3.4.0 through 3.8.1.
- Correlate router syslog and BGP neighbor state change events with known peer addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2009-2055 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://mailman.nanog.org/pipermail/nanog/2009-August/012719.html | Mailing List |
| http://securitytracker.com/id?1022739 | Broken Link |
| http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml | PatchVendor Advisory |
| http://mailman.nanog.org/pipermail/nanog/2009-August/012719.html | Mailing List |
| http://securitytracker.com/id?1022739 | Broken Link |
| http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-2055 | US Government Resource |
Track CVE-2009-2055 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-2055), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.