{ "id": "CVE-2010-3035", "sourceIdentifier": "psirt@cisco.com", "published": "2010-08-30T21:00:12.203", "lastModified": "2024-12-19T20:09:31.583", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211." }, { "lang": "es", "value": "Cisco IOS XR v3.4.0 hasta la versi\u00f3n v3.9.1, si BGP est\u00e1 activado, no maneja apropiadamente los atributos transitivos no reconocidos, lo que permite a atacantes remotos provocar una denegaci\u00f3n de servicio (\"peering reset\" o reinicio del hom\u00f3logo) a trav\u00e9s de un mensaje de anuncio de prefijos modificado, como se ha demostrado en la realidad en agosto del 2010 con el c\u00f3digo de tipo de atributo 99. Tambi\u00e9n conocido como Bug ID CSCti62211." } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "baseScore": 5.0, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "PARTIAL" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "cisaExploitAdd": "2022-03-25", "cisaActionDue": "2022-04-15", "cisaRequiredAction": "Apply updates per vendor instructions.", "cisaVulnerabilityName": "Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability", "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:*", "versionStartIncluding": "3.4.0", "versionEndIncluding": "3.9.1", "matchCriteriaId": "14636B6F-0D6A-4B1F-9F7E-C5A7445A5CFC" } ] } ] } ], "references": [ { "url": "http://mailman.nanog.org/pipermail/nanog/2010-August/024837.html", "source": "psirt@cisco.com", "tags": [ "Mailing List" ] }, { "url": "http://osvdb.org/67696", "source": "psirt@cisco.com", "tags": [ "Broken Link" ] }, { "url": "http://secunia.com/advisories/41190", "source": "psirt@cisco.com", "tags": [ "Broken Link" ] }, { "url": "http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtml", "source": "psirt@cisco.com", "tags": [ "Broken Link", "Vendor Advisory" ] }, { "url": "http://www.securitytracker.com/id?1024371", "source": "psirt@cisco.com", "tags": [ "Broken Link", "Third Party Advisory", "VDB Entry" ] }, { "url": "http://www.vupen.com/english/advisories/2010/2227", "source": "psirt@cisco.com", "tags": [ "Broken Link" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61443", "source": "psirt@cisco.com", "tags": [ "VDB Entry", "Vendor Advisory" ] }, { "url": "http://mailman.nanog.org/pipermail/nanog/2010-August/024837.html", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Mailing List" ] }, { "url": "http://osvdb.org/67696", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Broken Link" ] }, { "url": "http://secunia.com/advisories/41190", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Broken Link" ] }, { "url": "http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtml", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Broken Link", "Vendor Advisory" ] }, { "url": "http://www.securitytracker.com/id?1024371", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Broken Link", "Third Party Advisory", "VDB Entry" ] }, { "url": "http://www.vupen.com/english/advisories/2010/2227", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Broken Link" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61443", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "VDB Entry", "Vendor Advisory" ] } ] }