LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2009-2055: Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2009-2055 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

CVE-2009-2055 is a denial-of-service vulnerability in Cisco IOS XR when Border Gateway Protocol (BGP) is configured as a routing feature. Remote attackers can trigger conditions that disrupt BGP operation and affect routing availability on affected devices. For operators running IOS XR in production networks, this matters because BGP is often central to connectivity; a successful DoS can interrupt route exchange and degrade or drop traffic until the condition is cleared and services are restored.

Public detail is limited to the product, the BGP context, and the DoS outcome. Confirm exact exposure, fixed releases, and any configuration prerequisites against the vendor advisory before acting.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). In products of this class, the routing stack does not adequately validate certain input associated with BGP before processing it. An attacker who can reach the BGP-speaking interface or session path may send crafted or unexpected protocol data that the device mishandles, leading to resource exhaustion, process instability, or session failure that manifests as a denial of service.

Abuse does not require inventing specific packet formats here; the practical effect is remote disruption of BGP when the feature is enabled. Specifics of message types, session state, or exact failure modes must be taken from the vendor advisory rather than assumed. There is no documented ransomware use tied to this CVE in the provided facts.

Am I affected? How to find it in your systems

Cisco IOS XR typically runs on service-provider and large-enterprise routing platforms that participate in BGP—edge, core, or peering routers. Inventory every device running IOS XR and determine whether BGP is configured and active.

How to remediate

Patch first. Apply the updates specified by Cisco for this advisory, following the vendor’s installation and reload guidance for IOS XR. CISA’s required action is to apply updates per vendor instructions; treat the advisory as the authoritative source for fixed software and any mandatory configuration steps.

If you can't patch immediately

Reduce exposure until you can install the vendor update.

If your data may have been exposed

This CVE is described as a denial-of-service issue against BGP on Cisco IOS XR; the provided facts do not describe confidentiality impact or ransomware use. Actively exploited vulnerabilities can still lead to broader incidents if attackers use disruption as cover or pivot after gaining other access. If you have evidence of compromise on adjacent systems or credentials, follow your incident-response process, rotate affected secrets, and validate device integrity. You can run a free exposure scan of your email addresses against known breach data to check whether your identities appear in unrelated third-party breaches while you complete containment and patching.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS XR
WeaknessCWE-20
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities