PatchSiren cyber security CVE debrief
CVE-2010-3035 Cisco CVE debrief
CVE-2010-3035 is a Cisco IOS XR Border Gateway Protocol (BGP) denial-of-service vulnerability that CISA added to the Known Exploited Vulnerabilities (KEV) catalog on 2022-03-25. Because it is in KEV, it should be treated as a prioritized remediation item for any environment running affected Cisco IOS XR systems. CISA’s listed required action is to apply updates per vendor instructions.
- Vendor
- Cisco
- Product
- IOS XR
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-03-25
- Original CVE updated
- 2022-03-25
- Advisory published
- 2022-03-25
- Advisory updated
- 2022-03-25
Who should care
Network security teams, Cisco IOS XR administrators, and operators responsible for edge routing infrastructure that uses BGP on Cisco IOS XR.
Technical summary
The available official record identifies this issue as a denial-of-service vulnerability affecting Cisco IOS XR and specifically references BGP. The source corpus does not provide further technical detail, exploit mechanics, or impact scope beyond the KEV listing and vendor/product identification.
Defensive priority
High. CISA inclusion in KEV indicates known exploitation and elevates remediation urgency. The KEV entry sets a due date of 2022-04-15 for applying updates per vendor instructions.
Recommended defensive actions
- Inventory Cisco IOS XR deployments and confirm whether BGP is in use on exposed routing systems.
- Review Cisco vendor guidance for the affected IOS XR release trains and apply the recommended updates.
- Prioritize remediation for internet-facing or critical routing infrastructure first.
- Validate that change windows, rollback plans, and configuration backups are in place before upgrading.
- After remediation, confirm devices are on fixed software and monitor for BGP instability or unexpected service disruption.
Evidence notes
CISA KEV source item identifies the vulnerability as "Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability" and records vendorProject Cisco, product IOS XR, dateAdded 2022-03-25, dueDate 2022-04-15, and requiredAction "Apply updates per vendor instructions." The source item notes the related NVD record at https://nvd.nist.gov/vuln/detail/CVE-2010-3035. The provided official resource links include the CVE record, NVD detail page, and CISA KEV catalog.
Sources and references
Verified primary and authoritative sources
-
CVE-2010-3035 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2010-3035
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2010-3035 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2010-3035
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.