← Vulnerability feed

Vulnerability record · CVE-2010-3035 · published 30 August 2010

CVE-2010-3035: Cisco IOS XR BGP peering reset via unrecognized transitive attribute

Cisco · Ios Xr

Cisco IOS XR 3.4.0 through 3.9.1 mishandles unrecognized transitive BGP attributes when BGP is enabled, allowing a crafted prefix announcement to reset a BGP peering session. The flaw was demonstrated in the wild in August 2010 using attribute type code 99, and it matters because a single malformed announcement can tear down routing adjacencies on affected routers.

7.5 CVSS 3.1 High CISA KEV since 25 Mar 2022 EPSS 5.7% · top 7.3%
7.5CVSS 3.1 base score, v2 5.0
5.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
15References
16 Jun 2026Last modified by NVD

Description

Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is remotely exploitable without authentication, causes availability loss, and is listed in CISA KEV with in-the-wild demonstration, though it affects only a specific legacy IOS XR range.

What it is

Cisco IOS XR 3.4.0 through 3.9.1 mishandles unrecognized transitive BGP attributes when BGP is enabled, allowing a crafted prefix announcement to reset a BGP peering session. The flaw was demonstrated in the wild in August 2010 using attribute type code 99, and it matters because a single malformed announcement can tear down routing adjacencies on affected routers.

Impact

An attacker can force a denial of service by resetting BGP peering sessions, disrupting routing and reachability for networks served by the affected router. There is no confidentiality or integrity impact; the effect is availability loss.

Attack surface

The flaw is reachable over the network through BGP announcements sent to an affected router with BGP enabled; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The attacker only needs the ability to send a crafted prefix announcement carrying an unrecognized transitive attribute.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2022-03-25, and the description states it was demonstrated in the wild in August 2010. EPSS gives a 30-day probability of 0.05562 (92nd percentile), indicating elevated but not top-tier predicted activity.

What to do

  • Apply the Cisco IOS XR updates referenced in the vendor security advisory, upgrading beyond the affected 3.4.0 through 3.9.1 range.
  • If immediate patching is not possible, restrict BGP peering to trusted, authenticated neighbors and filter announcements carrying unexpected attribute type codes such as 99.
  • Monitor BGP session stability and alert on repeated peering resets to detect attempted or successful exploitation.
  • Review BGP route policy to drop or log prefixes with unrecognized transitive attributes before they reach the control plane.

Detection

  • Alert on BGP peering session resets or flaps on IOS XR routers, especially repeated resets from the same neighbor.
  • Inspect BGP update logs or packet captures for announcements containing attribute type code 99 or other unrecognized transitive attributes.
  • Correlate router syslog messages for BGP neighbor down events with inbound update activity from untrusted peers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2010-3035 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-3035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-3118Cisco IOS XR CDP packet parsing flaw allows adjacent code executionCisco IOS XR's Cisco Discovery Protocol implementation fails to properly validate string input in certain CDP message fields, allowing a stack overfl…KEVEPSS 12%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.6CVE-2020-3569Cisco IOS XR DVMRP IGMP packet handling memory exhaustionCisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash th…KEVEPSS 3.3%analysed8.6CVE-2020-3566Cisco IOS XR DVMRP IGMP queue flaw causes memory exhaustionCisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated…KEVEPSS 3.7%analysed8.0CVE-2018-0175Cisco IOS, IOS XE and IOS XR LLDP format string flawA format string vulnerability exists in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.5%analysed7.5CVE-2016-6415Cisco IOS IKEv1 memory disclosure via SA negotiationThe IKEv1 server implementation in Cisco IOS, IOS XE, IOS XR and PIX mishandles Security Association negotiation requests, allowing a remote attacker…KEVEPSS 88%analysed6.5CVE-2022-20821Cisco IOS XR health check RPM exposes Redis port without authenticationThe health check RPM in Cisco IOS XR Software opens TCP port 6379 by default when activated, exposing the Redis instance inside the NOSi container. A…KEVEPSS 11%analysed5.9CVE-2009-2055Cisco IOS XR BGP invalid attribute causes session reset DoSCisco IOS XR 3.4.0 through 3.8.1 fails to properly validate a BGP UPDATE message attribute, allowing a remote peer to reset BGP sessions. Because BGP…KEVEPSS 3.3%analysed

Source: NIST National Vulnerability Database (record CVE-2010-3035), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.