CVE-2009-2056: Low severity cisco ios xrv 9000 vulnerability
Published Aug 21, 2009
·Updated
Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.
Affected Software
33 affected components
Cisco IOS XR=3.6.1
Cisco IOS XR=3.7
Cisco IOS XR=3.1.0
Cisco IOS XR=3.2
Cisco IOS XR=3.6.2
Cisco IOS XR=3.2.50
Cisco IOS XR=3.6
Cisco IOS XR=3.4.0
Cisco IOS XR=3.5.2
Cisco IOS XR=3.5
Cisco IOS XR=3.2.3
Cisco IOS XR=3.3
Cisco IOS XR=3.2.1
Cisco IOS XR=3.4.2
Cisco IOS XR=3.7.2
Cisco IOS XR=3.4
Cisco IOS XR=3.4.1
Cisco IOS XR=3.2.4
Cisco IOS XR=3.7.0
Cisco IOS XR=3.4.3
Cisco IOS XR<=3.8.1
Cisco IOS XR=3.6.0
Cisco IOS XR=3.0.1
Cisco IOS XR=3.2.3
Cisco IOS XR=3.0
Cisco IOS XR=3.7.1
Cisco IOS XR=3.5.3
Cisco IOS XR=3.7.3
Cisco IOS XR=3.6.3
Cisco IOS XR=3.1
Cisco IOS XR=3.2.2
Cisco IOS XR=3.8.0
Cisco IOS XR=3.5.4
Remediation
Event History
Aug 21, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2056?
CVE-2009-2056 has a high severity rating as it allows remote authenticated users to trigger a denial of service condition.
2
How do I fix CVE-2009-2056?
To fix CVE-2009-2056, upgrade to a Cisco IOS XR version that is later than 3.8.1.
3
What software versions are affected by CVE-2009-2056?
CVE-2009-2056 affects multiple versions of Cisco IOS XR up to and including version 3.8.1.
4
Can CVE-2009-2056 be exploited remotely?
Yes, CVE-2009-2056 can be exploited by remote authenticated users.
5
What impact does CVE-2009-2056 have on Cisco devices?
Exploitation of CVE-2009-2056 can cause the affected Cisco device to crash, resulting in downtime and service disruption.