Vulnerability record · CVE-2010-3035 · published 30 August 2010
CVE-2010-3035: Cisco IOS XR BGP peering reset via unrecognized transitive attribute
Cisco · Ios Xr
Cisco IOS XR 3.4.0 through 3.9.1 mishandles unrecognized transitive BGP attributes when BGP is enabled, allowing a crafted prefix announcement to reset a BGP peering session. The flaw was demonstrated in the wild in August 2010 using attribute type code 99, and it matters because a single malformed announcement can tear down routing adjacencies on affected routers.
Description
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely exploitable without authentication, causes availability loss, and is listed in CISA KEV with in-the-wild demonstration, though it affects only a specific legacy IOS XR range.
What it is
Cisco IOS XR 3.4.0 through 3.9.1 mishandles unrecognized transitive BGP attributes when BGP is enabled, allowing a crafted prefix announcement to reset a BGP peering session. The flaw was demonstrated in the wild in August 2010 using attribute type code 99, and it matters because a single malformed announcement can tear down routing adjacencies on affected routers.
Impact
An attacker can force a denial of service by resetting BGP peering sessions, disrupting routing and reachability for networks served by the affected router. There is no confidentiality or integrity impact; the effect is availability loss.
Attack surface
The flaw is reachable over the network through BGP announcements sent to an affected router with BGP enabled; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The attacker only needs the ability to send a crafted prefix announcement carrying an unrecognized transitive attribute.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-03-25, and the description states it was demonstrated in the wild in August 2010. EPSS gives a 30-day probability of 0.05562 (92nd percentile), indicating elevated but not top-tier predicted activity.
What to do
- Apply the Cisco IOS XR updates referenced in the vendor security advisory, upgrading beyond the affected 3.4.0 through 3.9.1 range.
- If immediate patching is not possible, restrict BGP peering to trusted, authenticated neighbors and filter announcements carrying unexpected attribute type codes such as 99.
- Monitor BGP session stability and alert on repeated peering resets to detect attempted or successful exploitation.
- Review BGP route policy to drop or log prefixes with unrecognized transitive attributes before they reach the control plane.
Detection
- Alert on BGP peering session resets or flaps on IOS XR routers, especially repeated resets from the same neighbor.
- Inspect BGP update logs or packet captures for announcements containing attribute type code 99 or other unrecognized transitive attributes.
- Correlate router syslog messages for BGP neighbor down events with inbound update activity from untrusted peers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2010-3035 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3035 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3035), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.