Home Cisco CVE-2010-3035
CRITICAL: THIS VULNERABILITY IS ACTIVELY BEING EXPLOITED IN THE WILD (CISA KEV CATALOG)
Back to Cisco

CVE-2010-3035

Exploited

Cisco IOS XR - BGP

Cisco CVSS 7.5 Updated April 30, 2026

Executive Risk Summary

"A vulnerability in Cisco IOS XR 3.4.0 through 3.9.1 allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement. This vulnerability can be exploited by sending a malicious BGP update with an unrecognized transitive attribute, such as attribute type code 99."

Anticipated Attack Path

  1. 1. Reconnaissance: Identify vulnerable Cisco IOS XR devices with BGP enabled
  2. 2. Exploitation: Send a crafted BGP update with an unrecognized transitive attribute
  3. 3. Denial of Service: BGP peering session reset

Am I Vulnerable?

  • Verify Cisco IOS XR version and BGP configuration
  • Monitor BGP peering sessions for unexpected resets
  • Apply Cisco-recommended patches or workarounds

Operational Audit Arsenal

Target Type Network Device
Target Asset bgp
Standard Path Cisco IOS XR

Manual Verification Required

This is a non-Windows asset (Cisco). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Network connectivity disruption possible during patch application

Internal Work Notes

CVE-2010-3035: Cisco IOS XR BGP vulnerability - potential for denial of service via crafted BGP update

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Cisco Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.