CVE-2009-2056
Cisco IOS XR < 3.8.1 - Authenticated Denial of Service via BGP UPDATE Message
Title source: llmDescription
Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1022756
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml
Scores
EPSS
0.0134
EPSS Percentile
68.3%
Details
CWE
CWE-264
Status
published
Products (32)
cisco/ios_xr
3.0
cisco/ios_xr
3.0.1
cisco/ios_xr
3.1
cisco/ios_xr
3.1.0
cisco/ios_xr
3.2
cisco/ios_xr
3.2.1
cisco/ios_xr
3.2.2
cisco/ios_xr
3.2.3 (2 CPE variants)
cisco/ios_xr
3.2.4
cisco/ios_xr
3.2.50
... and 22 more
Published
Aug 21, 2009
Tracked Since
Feb 18, 2026