LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2010-3035: Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2010-3035 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

CVE-2010-3035 is a denial-of-service vulnerability in Cisco IOS XR when Border Gateway Protocol (BGP) is configured as a routing feature. Improper input validation (CWE-20) can allow a remote attacker to disrupt BGP operation and affect routing availability on affected devices. For operators running IOS XR in production networks, this matters because BGP instability can interrupt reachability and force recovery work under pressure. Confirm exact product and configuration details against the vendor advisory.

How it works

The weakness is improper input validation in the BGP handling path of Cisco IOS XR. When BGP is enabled, crafted or unexpected protocol input that is not adequately checked can cause the routing process or related services to fail, producing a denial-of-service condition rather than a controlled rejection of bad data.

An attacker who can send BGP-related traffic to a vulnerable device may trigger that failure remotely. Public detail in the provided record does not describe packet formats, session requirements, or exploit mechanics; treat any such claims as unverified unless they appear in the vendor advisory. The practical outcome is loss of BGP stability or process availability on the affected router, which can cascade into routing disruption for networks that depend on that device.

Am I affected? How to find it in your systems

Cisco IOS XR is commonly deployed on service-provider and large-enterprise edge and core routers where BGP is used for inter-domain or large-scale internal routing. Inventory every platform running IOS XR and determine whether BGP is configured.

For exploitation signs, watch BGP session resets, unexpected process restarts or core dumps on the routing stack, sudden loss of prefixes, and syslog or telemetry spikes correlated with external peering activity. These symptoms are generic to BGP DoS and process faults; confirm interpretation against vendor guidance and your baseline behavior. There is no substitute for matching your exact image and configuration to the advisory.

How to remediate

Patch first. Apply the updates Cisco specifies for CVE-2010-3035 on every affected IOS XR system, following the vendor’s install and reload procedures for your platform. CISA’s required action is to apply updates per vendor instructions; schedule maintenance windows accordingly and verify post-upgrade BGP adjacency and route tables.

If the advisory lists workarounds or feature-specific notes, implement those only as described by Cisco; do not invent configuration knobs.

If you can't patch immediately

Reduce attack surface until you can upgrade. Segment management and control-plane access so BGP speakers are not reachable from untrusted networks. Use infrastructure ACLs, control-plane policing, and strict neighbor definitions so only known peer IPs can form sessions. Where a WAF or virtual patching appliance sits in front of management paths, it will not replace IOS XR fixes for BGP on the router itself; focus on network-layer filtering and peer restriction.

These steps lower likelihood and impact; they are not a permanent substitute for the vendor update.

If your data may have been exposed

This record describes a denial-of-service issue and does not document ransomware use or confidentiality impact. Actively exploited vulnerabilities can still lead to broader incidents if attackers use disruption as cover or pivot after gaining another foothold. If you suspect compromise beyond BGP instability, follow your incident response process: preserve logs, isolate affected devices, and verify integrity of configurations and images. You can run a free exposure scan of your email addresses against known breach data to see whether credentials or identities appear in unrelated third-party breaches while you complete containment and patching.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS XR
WeaknessCWE-20
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities