{"id":"CVE-2009-2055","aliases":[],"url":"https://o3.security/vulnerability/CVE-2009-2055","summary":"Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.","details":"Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.","published":"2009-08-19T17:00:00.000Z","modified":"2026-01-12T20:39:47.917Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.03326,"percentile":0.87673,"asOf":"2026-08-25"},"cisaKev":{"dateAdded":"2022-03-25","dueDate":"2022-04-15","knownRansomwareCampaignUse":false},"exploitsKnown":2,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"http://mailman.nanog.org/pipermail/nanog/2009-August/012719.html"},{"type":"WEB","url":"http://securitytracker.com/id?1022739"},{"type":"ADVISORY","url":"http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-2055"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-01-12T20:39:47.917Z"}}