Cyber Resilience

CVE-2010-3035

Cisco Ios Xr 3.4.0 – 3.9.1

CISA KEVActive ExploitationEUVD Exploited
Published
30 August 2010
Modified
22 April 2026
KEV Added
25 March 2022
Patch / advisory
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.056 92th percentile
Risk Priority 80 floored blend · peak EPSS

Summary

CVE-2010-3035 is a high-severity an unspecified weakness vulnerability in Cisco Ios Xr. Its CVSS base score is 7.5 (High).

Operationally, ranked in the top 8% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

EU & UK References

Vulnerability Data

Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in…

more

August 2010 with attribute type code 99, aka Bug ID CSCti62211.

CWE(s)
KEV Date Added
25 March 2022

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1498 Network Denial of Service Impactconfidence: HIGH
Malformed BGP prefix announcements with unrecognized transitive attributes trigger peering resets, enabling network denial of service.
inferred from description · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2009-2055Same product: Cisco Ios Xrboth on KEV
CVE-2025-20115Same product: Cisco Ios Xr
CVE-2024-20304Same product: Cisco Ios Xr
CVE-2026-20074Same product: Cisco Ios Xr
CVE-2024-20319Same product: Cisco Ios Xr
CVE-2023-20233Same product: Cisco Ios Xr
CVE-2024-20317Same product: Cisco Ios Xr
CVE-2024-20489Same product: Cisco Ios Xr
CVE-2024-20390Same product: Cisco Ios Xr
CVE-2025-20138Same product: Cisco Ios Xr

Affected Assets

cisco
ios xr
3.4.0 — 3.9.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References