Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 8.4(7)31 – 04/08/2016

Files:  asa847-31-k8.bin, asa847-31-smp-k8.bin

Defects resolved since 8.4(7)30:

 

CSCux41145

Evaluation of pix-asa for OpenSSL December 2015 Vulnerabilities

 

 

Revision:  Version 8.4(7)30 – 01/15/2016

Files:  asa847-30-k8.bin, asa847-30-smp-k8.bin

Defects resolved since 8.4(7)29:

 

CSCux29978

Cisco ASA IKEv1 and IKEv2 Buffer Overflow Vulnerability

 

CSCux42019

Cisco ASA IKEv1 and IKEv2 Buffer Overflow Vulnerability

 

 

Revision:  Version 8.4(7)29 – 10/21/2015

Files:  asa847-29-k8.bin, asa847-29-smp-k8.bin

Defects resolved since 8.4(7)28:

 

CSCus47259

Cisco ASA XAUTH Bypass Vulnerability

 

CSCus94026

ISAKMP SERVER traffic from codenomicon crashes ASA

CSCut03495

ASA traceback in ThreadName:ci/console,while pinging DNS Server name

CSCut46019

MARCH 2015 OpenSSL Vulnerabilities

 

CSCuu07799

Traceback: mem_get_owner+104 at slib/../finesse/snap_api.h:163

CSCuu83280

Evaluation of OpenSSL June 2015

 

 

 

Revision:  Version 8.4(7)28 – 04/08/2015

Files:  asa847-28-k8.bin, asa847-28-smp-k8.bin

Defects resolved since 8.4(7)26:

 

CSCtz48533

Cisco ASA Challenge-Response Tunnel Group Selection Bypass Vulnerability

 

CSCuh24695

WebVPN portal DOM based Cross-Site-Scripting Issue

 

CSCuj28861

Cisco ASA Malformed DNS Reply Denial of Service Vulnerability

 

CSCul02601

ASA Crash in checkheaps due to snmp component

 

CSCuq35090

Webvpn: Support for XFRAME in additional portal and CSD pages

 

CSCur21069

Failover units should accept only traffic coming from the peer

 

CSCur42776

Mac version smart-tunnel uses SSLv3 which is  a vulnerability

 

CSCur68226

ASA SMTP inspection should not disable TLS by default

 

CSCus03141

ipsec-datapath:TFW management connection via VPN takes a few minutes

 

CSCus06652

ASA5580-20 8.4.7.23: Traceback in Thread Name: ssh

 

CSCus42901

JANUARY 2015 OpenSSL Vulnerabilities

 

CSCus51289

ASA: Traceback when removing manual NAT rule

 

CSCus95290

ASA / denial of service against xml parser.

 

CSCut45114

2048-byte block leak if DNS server replies with "No such name"

 

 

 

 

 

Revision:  Version 8.4(7)26 – 02/03/2015

Files:  asa847-26-k8.bin, asa847-26-smp-k8.bin

Defects resolved since 8.4(7)23:

 

CSCug51375

ASA SSL: Continues to accept SSLv3 during TLSv1 only mode

CSCui27525

Idle timer and half-closed idle timer reset by out of sequence SYN

CSCun43072

ASA5585-SSP60 Traceback in Thread Name SSH on Capture Command

CSCuq21016

Local pool address not released -> Duplicate local pool address found

CSCuq77655

1550 block leak occur if DNS replies "refused" query response

CSCuq80639

ASA5580 speed nonegotiate settings kept link down after shut/no shut

CSCuq98633

Object Group Search causing legitimate traffic to be dropped by ACL

CSCur16308

DHCP Relay reloads after changing server interface

CSCur23709

ASA  : evaluation of SSLv3 POODLE vulnerability

CSCur59704

ASA: Traceback in idfw_proc

CSCur64589

DATAPATH Traceback in snp_mp_svc_udp_upstream_data function

CSCur64659

ASA Traceback in Thread Name: DATAPATH-6-2544

CSCus08101

ASA: evaluation of Poodle Bites in TLSv1

CSCus42901

JANUARY 2015 OpenSSL Vulnerabilities

 

 

Revision:  Version 8.4(7)23 – 09/26/2014

Files:  asa847-23-k8.bin, asa847-23-smp-k8.bin

Defects resolved since 8.4(7)22:

 

CSCty17881

vpn-sessiondb detail missing Filter Name after IKEv1 rekey

CSCtz53586

ASA: Traceback when out of stack memory with call-home configured

CSCug25761

ASA has inefficient memory use  when cumulative AnyConnect session grows

CSCuh79288

ASA 9.1.2 DHCP - Wireless Apple devices are not getting an IP via DHCPD

CSCuh84378

ASA: Last packet in PCAP capture file not readable

CSCui44095

ASA 9.1: timer app id was corrupted causing to Dispatch Unit traceback

CSCui63001

ASA traceback in Thread Name: fover_parse during command replication

CSCul04263

ASA Webvpn CIFS vnode_create: VNODE ALLOCATION LIMIT 100000 REACHED!

CSCul46971

ASA Transparent mode doesn't pass DHCP discover message

CSCun11074

ASA:Tracebacks in thread dispatch unit due to SunRPC inspection

CSCun78551

Cisco ASA Information Disclosure Vulnerability

CSCun85465

'ASA modifies Request Host Part under 'ACK' packet for SIP connection'

CSCun86984

ASA 5505 u-turned/hairpinned conn counts toward license local-host limit

CSCuo09383

ASA WebVPN Memory leak leading to Blank Portal Page/AnyConnect failure

CSCuo11778

ENH: Add "speed nonegotiate" command for fiber interfaces on ASA5585

CSCuo27866

Traceback on DATAPATH-7-1524 Generating Botnet Filter Syslog

CSCuo45321

ASA allows IKEv1 clients to bypass address assignment, causing conflict

CSCuo46136

ASA does not relay BOOTP packets

CSCuo48593

ASA with SFP+4GE-SSM sends flow-control packets at line rate

CSCuo54393

ASA: HTTP searchPendingOrders.do function failing over WebVPN

CSCuo91763

ASA allows to empty an access-list referenced elsewhere

CSCuo95602

Standby ASA traceback on Fover_Parse with Botnet Filter

CSCup00433

Failover Standby unit has higher memory utilization

CSCup01676

ASA: Traceback in DATAPATH

CSCup07330

ASA: no auth prompt when accessing internet website using ASA-CX

CSCup08262

9.0(4)5 - Unable to access internal site via clientless SSLVPN

CSCup13265

ASA - Traceback in thread name: sch_prompt anonymous reporting

CSCup22532

Multiple Vulnerabilities in OpenSSL - June 2014

CSCup26021

TCP intercept does not work after embryonic connection ends

CSCup35713

ASA tmatch_summary_alloc block leak in binsize 1024

CSCup36829

Cisco ASA SSL VPN Portal Customization Integrity Vulnerability

 

CSCup43257

ASA Traceback in Thread name: ci/console while modifying an object-group

CSCup48772

ASA - Wrong object-group migration during upgrade from 8.2

CSCup48979

ASA - Permitting/blocking traffic based on wrong IPs in ACL

CSCup55377

ASA: Traceback Page Fault in vpnfol_thread_msg on Standby ASA

CSCup59017

ASA with ACL optimization traceback in "fover_parse" thread

CSCup68697

WebVPN: uploading customized portal.css breaks the portal login page

CSCup74532

ASA failover standby device reboots due to delays in config replication

CSCuq03216

IPsecOverNatT tunnel disappears after ASA failovers

CSCuq04306

Smart Tunnels Spawn "UNKNOWN Publisher" Warning w/Java 7 Update 60

CSCuq05768

Using "?" to list files in directory with thousands of files causing hog

CSCuq09352

vbscript getting caught in loop when passing thru ASA WebVPN Rewriter

CSCuq26046

ASA - Traceback in thread name SSH while changing NAT configuration

CSCuq28582

Cisco ASA Privilege Escalation

CSCuq29136

ASA: Entering Query String on /+CSCOE+/logon.html disclose information

CSCuq34213

Double Free when processing DTLS packets

CSCuq34226

OpenSSL Zero-Length Fragments DTLS Memory Leak Denial of Service Vuln

CSCuq38807

ASA Radius Access-Request contains both User-Password and CHAP-Password

CSCuq46931

LDAP CLI: Quotes removed if ldap attribute-map name has spaces

CSCuq47035

ASA:Incorrect link status in show failover o/p with monitoring disabled

CSCuq57188

ASA returns wrong content-length for cut-thru proxy authentication page

CSCuq59582

ASA:Multicast traffic silently dropped due to Promiscuous Mode: Disabled

 

 

Revision:  Version 8.4(7)22 – 07/11/2014

Files:  asa847-22-k8.bin, asa847-22-smp-k8.bin

Defects resolved since 8.4(7)15:

 

CSCui60514

ASA 5585 SSP-IPS 9.x Gig interfaces do not come up after module reset

CSCul22237

ASA may drop all traffic with Hierarchical priority queuing

CSCum12633

webvpn issue,part of the http request not sent by the client to ASA

CSCum70178

Datapath:Observing Deadlock in different DATAPATH threads

CSCum75214

ASA5585-SSP60 Teardown process is delayed under heavy traffic condition

CSCum80899

ASA: Watchdog traceback in Unicorn Admin Handler with TopN host stats

CSCum85047

Traceback in Thread: IPsec message handler with rip-tlog_event_allocate

CSCun10189

Ping doesn't work between peer IPs when answer-only is configured

CSCun10844

Java rewriting takes too much time

CSCun19025

ASA WebVPN login page XSS vulnerability

CSCun24971

ASA not passing IPv6 traffic when connected to Anyconnect

CSCun31725

ASA using IKEv2 rejects multiple NAT_DETECTION_SOURCE_IP payloads

CSCun41817

Hash calculated for multiple ACEs on ASA are same

CSCun44108

Unable to access webvpn portal when CSD and IE content advisor enabled.

CSCun66161

5585-20 8.4.7.11 traceback in Thread Name Datapath w/ DCERPC inspection

CSCun71442

MEMLEAK: AnyConnect when authenticating

CSCun71586

MEMLEAK: 128 byte leaks when requesting IPv6 address for AnyConnect

CSCun88276

High CPU with IKE daemon Process

CSCun96170

ASA 8.4.6: Traceback with fover_FSM_thread

CSCuo00904

ASA Page Fault: Invalid Permission in thread name DATAPATH

CSCuo03555

SNMP: cpmCPUTotal5sec/1min/5min return "0"

CSCuo03569

VPN client firewall and split-tunneling mishandle "inactive" acl rules

CSCuo04965

Clientless scrollbar on right hand side of the screen doesn't render

CSCuo08511

ASA 9.0.4.1 traceback in webvpn datapath

CSCuo11057

IPsec transform sets mode changes from transport to tunnel after editing

CSCuo19916

ASA - Cut Through Proxy sends empty redirect w/ Virtual HTTP and Telnet

CSCuo49385

Multicast - ASA doesn't populate mroutes after failover

CSCuo61372

ASA doesn't send invalid SPI notify for non-existent NAT-T IPSec SA

CSCuo68521

ASA: Page fault traceback in Dispatch Unit

CSCup22532

Multiple Vulnerabilities in OpenSSL - June 2014

 

 

Revision:  Version 8.4(7)15 – 04/09/2014

Files:  asa847-15-k8.bin, asa847-15-smp-k8.bin

Defects resolved since 8.4(7)3:

 

CSCsk87165

ENH - Add device serial number and platform string to show run output

CSCtc18329

ACL renamed but syslog doesn't reflect new name

CSCtd57392

Unable to create policy map depending on existing maps and name

CSCtg63826

ASA: multicast 80-byte block leak in combination with phone-proxy

CSCtr80800

Improve HTTP inspection's logging of proxied HTTP GETs

CSCtu37460

Backup Shared  License Server unable to open Socket

CSCtw75734

tmatch compile thread assertion in "stride_terminal_node.c"

CSCtz70573

SMP ASA traceback on periodic_handler for inspecting icmp or dns trafic

CSCtz92586

A warning message is needed when a new encryption license is applied

CSCua92694

Traceback on Configuration Manipulation over Telnet/SSH Sessions

CSCub38407

Add text section to coredump

 

CSCud16208

ASA 8.4.4.5 - Traceback in Thread Name: Dispatch Unit

CSCud37992

HTTP Deep Packet Inspection Denial of Service Vulnerability

CSCue48441

Mem Leak: ikev2_fo_parse_sa_message_id_data_v1

CSCug48732

Traceback when loading configuration from TFTP multiple contexts

CSCug49382

IKEv2 : L2L tunnel fails with error "Duplicate entry in Tunnel Manager"

CSCuh03193

ASA - Not all GRE connections are replicated to the standby unit

CSCuh32106

ASA KCD is broken in 8.4.5 onwards

CSCuh70040

Renew SmartTunnel Web Start .jnlp Certificate 9/7/2013

CSCui00048

ASA traceback with 'debug menu webvpn 160' command

CSCui04520

WebVpn: javascript parser error while rewriting libmin.js

CSCui08074

WebVPN doesn't accept connections, Unicorn Proxy Thread no longer exists

CSCui20863

ENH: ASA should send flow-update for short-lived flows

CSCui24669

ASA PAT rules are not applied to outbound SIP traffic

CSCui55510

ASA traceback in Thread Name: DATAPATH-2-1140

CSCuj10294

CSCul37888Traceback in DATAPATH caused by HTTP Inspection

CSCuj33496

Privillage level 0 users getting full access

 

CSCuj33701

traceback ABORT(-87): strcpy_s: source string too long for dest

CSCuj35576

ASA OSPF route stuck in database and routing table

CSCuj42515

ASA reloads on Thread name: idfw_proc

CSCuj45406

ASA: Page fault traceback with 'show dynamic-filter dns-snoop detail'

CSCuj60572

Unable to assign ip address from the local pool due to 'Duplicate local'

CSCuj68055

ASA traceback in Thread Name: ssh on modifying service object

CSCuj68420

ASA SMR: Multicast traffic for some groups stops flowing after failover

CSCuj71626

ST not injected in mstsc.exe on 64-bit Win 8 IE 10 when started TSWebApp

CSCuj72638

ASA-SM - TFW Dropping jumbo mcast traffic with 3 intf in a bridge group

CSCuj82692

ASA 8.4.7 - Traceback with assertion in thread name Dispatch Unit

CSCuj83344

ASA traceback in Thread name - netfs_thread_init

CSCuj88114

WebVPN Java rewriter issue: Java Plugins fail after upgrade to Java 7u45

CSCuj99263

Wrong ACL seq & remarks shown when using Range object w/ object-group

CSCul02052

ASA fails to set forward address in OSPF route redistrubution

CSCul05200

Webvpn rewriter some links from steal.js are mangled incorrectly

CSCul08896

ASA Webvpn: Rewriter issue with dynamic iframes

CSCul10352

OpenSSH vulnerability CVE-2012-0814: Debug messages with key info

CSCul17354

Traceback after upgrade from pre-8.3 to 8.3 and above

CSCul18059

Object Group Search may cause ACL to be matched incorrectly

CSCul25576

ASA: Page fault traceback after running show asp table socket

CSCul26755

INSPECT ICMP ERROR  ICMP HEADER AFTER UN_NAT DOES NOT MATCH IP DST ADDR

CSCul28082

ASA traceback in Thread Name: DATAPATH due to double block free

CSCul33074

ASA: Hitless upgrade fails with port-channels

CSCul34143

ENH: Need to optimize messages printed on upgrade from 8.2- to 8.3+

CSCul35600

WebVPN: sharepoint 2007/2010 and Office2007 can't download/edit pictures

CSCul37888

traffic does not match time-rang access-list configured with policy-maps

CSCul41447

ASA: Memory leak with WebVPN and HTTP server enabled simultaneously

CSCul47481

ASA WebVPN Login portal returns to login page after successful login

CSCul49796

ASA Tranparent A/A - Replicated MAC addresses not deleted after timeout

CSCul55863

ASA with ICMP insp. drops replies with 'seq num not matched' code

CSCul60058

Case sensitivity check missing for Web Type ACL and Access-group

CSCul60950

IPSEC VPN - One crypto ACE mismatch terminates all Phase2 with that peer

CSCul61939

Webvpn: ASA  fails to rewrite javascript tag correctly

CSCul62357

ASA fails to perform KCD SSO when web server listens on non-default port

CSCul64980

Acct-stop for VPN session doesn't send out when failover occurred

CSCul65069

ASA Assert Traceback in Dispatch Unit during LU Xlate replication

CSCul68363

EIGRP: Auth key with space replicates to Secondary with no space

CSCul70062

Capture Isakmp w/ match statement cause Standby to reload at replication

CSCul70099

ASA SSL VPN Privilege Escalation Vulnerability

 

CSCul73785

WEBVPN multiple issues with LMS application

CSCul74286

ASA: Phy setting change on member interfaces not seen on port-channel

CSCul83331

Redundant IFC not Switching Back

CSCul84216

ASA - Remote access VPN sessions are not replicated to Standby unit

CSCul90151

ASA EIGRP redistribute static shows up as internal route

CSCul95239

Copying configuration to running-config fails

CSCul96580

ASA tears down SIP signaling conn w/ reason Connection timeout

CSCul98420

'Route-Lookup' Behavior Assumed for Twice NAT with Identity Destination

CSCum00556

Page fault traceback in DATAPATH under DoS, rip qos_topn_hosts_db_reset

CSCum00826

ASA reloads on Thread name: idfw_proc

CSCum01313

ASA drops DHCP Offer packet in ASP when nat configured with "Any"

CSCum11724

secondary standby looses his cluster license after upgrade to 8.4.(7.3)

CSCum24634

IKEv1 - Send INVALID_ID_INFO when received P2 ID's not in crypto map

CSCum24760

ASA policy-map action not applied correctly after config change

CSCum26955

Webvpn: Add permissions attribute to portforwarder jar file

CSCum26963

Webvpn: Add permissions attribute to mac smart-tunnel jar

CSCum32334

WebVPN: ASA webVPN fails to rewrite dynamic content of pubmed website

CSCum35118

ASA:Traceback in Thread Name: DATAPATH-23-2334

CSCum37080

Traceback in IKEv2 Daemon with AnyConnect Failure

CSCum54163

IKEv2 leaks embryonic SAs during child SA negotiation with PFS mismatch

CSCum60784

ASA traceback on NAT assert on file nat_conf.c

CSCum82760

ASA traceback in Unicorn Admin Handler

CSCum82840

ASA: Traceback in pix_flash_config_thread when upgrading with names

CSCum84247

ASA - VPN session leak for IKEv2 if L2L sessions land on RA tunnel group

CSCum93731

ASA 9.1.3 SNMP Traceback in Thread Name: SNMP

CSCum94542

Traceback in Thread Name: ci/console

CSCun04658

Assigned IP in show vpn-sessiondb anyconnect is missing.

CSCun08017

ASA WebVPN memory leak - blank portal page

CSCun11323

ASA: Traceback in aware_http_server_thread after upgrade

CSCun16022

ASA traceback in Thread Name: IKE Daemon: with CX redirect in place.

CSCun17705

Regex modification within context causes ASA traceback

CSCun18948

ASA EIGRP route stuck after neighbour disconnected

CSCun41702

L2TP/IPSec connection is failed when there is PAT router.

 

 

Revision:  Version 8.4(7)3 – 10/24/2013

Files:  asa847-3-k8.bin, asa847-3-smp-k8.bin

Defects resolved since 8.4.7:

 

CSCtw82904

ESP packet drop due to failed anti-replay checking after HA failovered

CSCua85555

Cookie usage in SSL VPN

 

CSCub43580

Traceback during child SA rekey

CSCug19491

ASA drops some CX/CSC inspected HTTP packets due to PAWS violation

CSCug89590

Hostscan 3.1.03104 does not detect Kaspersky AV 6.0

CSCuh12279

ASA: Data packets with urgent pointer dropped with IPS as bad-tcp-cksum

CSCuh21682

ASA traceback with less PAT with huge traffic

CSCuh49686

slow memory leak due to webvpn cache

CSCui00618

ASA does not send Gratuitous ARP(GARP) when booting

CSCui01258

limitation of session-threshold-exceeded value is incorrect

CSCui12430

ASA: SIP inspection always chooses hairpin NAT/PAT for payload rewrite

CSCui22862

ASA traceback when using "Capture Wizard" on ASDM

CSCui25277

ASA TFW doesn't rewrite VLAN in BPDU packets containing Ethernet trailer

CSCui27773

Intermittently users not allowed to login due to hostscan data limit

CSCui38495

ASA Assert in Checkheaps chunk create internal

CSCui41794

ASA A/A fover automatic MAC address change causes i/f monitoring to fail

CSCui45340

ASA-SM assert traceback in timer-infra

CSCui46469

ASA: Multicast traffic silently dropped on port-channel interfaces

CSCui55978

ASA 8.2.5 snmpEngineTime displays incorrect values

CSCui57181

ASA/IKEv1-L2L: Do not allow two IPsec tunnels with identical proxy IDs

CSCui63322

ASA Traceback When Debug Crypto Archives with Negative Pointers

CSCui66657

Safari crashes when use scroll in safari on MAC 10.8 with smart-tunnel

CSCui70562

AnyConnect Copyright Panel and Logon Form message removed after upgrade

CSCui77398

Cisco ASA Crafted ICMP Packet Denial of Service Vulnerability

CSCui80059

ASA traceback in pix_startup_thread

CSCui80835

ASA drops packet as PAWS failure after incorrect TSecr is seen

CSCui88578

Failure when accessing CIFS share with period character in username

CSCui91247

ASA does not pass calling-station-id when doing cert base authentication

CSCui94757

ASA tears down SIP signaling conn w/ reason Connection timeout

CSCui98879

Clientless SSL VPN:Unable to translate for Japanese

CSCuj06865

ASA traceback when removing more than 210 CA certificates at once

CSCuj08004

AnyConnect states: "VPN configuration received... has an invalid format"

CSCuj13728

ASA unable to remove ipv6 address from BVI interface

CSCuj16320

ASA 8.4.7 Multi Context TFW not generating any syslog data

CSCuj23632

Certificate CN and ASA FQDN mismatch causes ICA to fail.

CSCuj34124

Sustained high cpu usage in Unicorn proxy thread with jar file rewrite

CSCuj34241

no debug all, undebug all CLI commands doesnt  reset unicorn debug level

CSCuj43339

Add X-Frame-Options: SAMEORIGIN to ASDM HTTP response

CSCuj44998

ASA drops inbound traffic from AnyConnect Clients