Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.6(2)13 – 03/10/2017

Files:  asa962-13-smp-k8.bin

Defects resolved since 9.6(2)11:

 

CSCvd41417

OCSP Responder certificate must contain OCSPSigning EKU

CSCvd41423

CRL must be signed by certificate containing cRLSign key usage

 

 

Revision:  Version 9.6(2)11 – 02/22/2017

Files:  asa962-11-smp-k8.bin

Defects resolved since 9.6(2)7:

 

CSCum28756

ASA: Auth failures for SNMPv3 polling after unit rejoins cluster

CSCuu48197

ASA: Stuck uauth entry rejects AnyConnect user connections

CSCuv61791

CWS redirection on ASA may corrupt sequence numbers with https traffic

CSCuw88759

ASA: Protocol and Status showing UP without connecting the interface

CSCuy55468

Unicorn Proxy Thread causing CP contention

CSCva22048

ASA: SIP Call Drops with PAT when same media port used in multiple calls

CSCva47608

SCTP MH:pin hole removed and added freq on standby with dual nat

CSCva71783

ICMP error packets in response to reply packets are dropped

CSCva92975

ASA 5585-60 dropping out of cluster with traceback

CSCva98240

SIP: Address from Route: header not translated correctly

CSCvb13865

ENH:Support to validate certificate verify signature that uses 512 hash

CSCvb15265

ASA Page fault traceback in Thread Name: DATAPATH

CSCvb25139

IPv6 DNS packets getting malformed when DNS inspection is enabled.

CSCvb40847

ASA not sending Authen Session End log if user logs out manually

CSCvb43120

ASA Traceback in Checkheaps Thread

CSCvb47006

ASA traceback observed on auto-update thread.

CSCvb50301

ASA traceback at Thread Name: rtcli

CSCvb52157

viewer_dart.js file not loading correctly

CSCvb52492

VPN tunnels are lost after failover due to OSPF route issue

CSCvb58087

Object-group-search redundant service group objects are incorrectly removed

CSCvb74249

ASA dropping traffic with TCP syslog configured in multicontext mode

CSCvb75685

EZVPN NEM client can't reconnect after "no vpnclient enable" is entered

CSCvb78614

4GE-SSM RJ45 interface may drop traffic due to interface "rate limit drops"

CSCvb87586

Failed to ssh management interface after failover and plug-in/out

CSCvb88126

ASA: Stuck uauth entry rejects AnyConnect connection despite fix for CSCuu48197

CSCvb89988

WebVPN: Internal page login button not working through rewriter

CSCvb92125

ASA drops DNS PTR Reply with reason Label length exceeded during rewrite

CSCvb92823

ASA SIP inspection may delay transmission of 200 OK when embedded with NOTIFY

CSCvc00689

ASA : memory leak due to ikev2

CSCvc01835

Interfaces show down and not associated on MIO

CSCvc05005

ASA cluster TCP/SSL ports are not displayed on LISTEN state

CSCvc06150

ASA unable to add multiple attribute entries in a certificate map

CSCvc07330

ASAv traceback randomly

CSCvc14448

9.6.2 - Traceback during AnyConnect IKEv2 Performance Test

CSCvc14502

ASA multicontext disallowing new conns with TCP syslog unreachable and logging permit-hostdown set

CSCvc16330

ASA-SM 9.5.2 inspect-sctp licensing breaks existing deployments

CSCvc19318

ASA traceback at Thread Name: sch_syslog

CSCvc23838

Cisco ASA Heap Overflow in Webvpn CIFS

CSCvc24657

MIB object cempMemPoolHCUsed disappeared

CSCvc24788

ASA: OspfV3 routes are not getting installed

CSCvc25281

Error synchronizing the SNMPv3 user after rebooting a cluster unit

CSCvc25409

ASA memory leak in CloneOctetString when using SNMP polling

CSCvc33796

Implement speed improvements for ACL and NAT table compilation

CSCvc36535

ASA traceback in Thread Name: ssh, rip igb_disable_rx_queues after no shutdown of interface

CSCvc36805

Firepower Threat Defense (FTD) IKEv2 NAT-T gets disabled after reboot

CSCvc39121

Anyconnect address assignment fails using external DHCP server when ASA is in Multi-context Mode

CSCvc44240

ASA clustering: mac-address cmd is ignored on spanned port-channel interface in 9.6.2

CSCvc48640

ASA not update access-list dynamically when forward-reference enable is configured

CSCvc52072

Webvpn portal not displayed corrrectly for connections landing on default webvpn group.

CSCvc52272

ASA inspection-MPF ACL changes are not getting ordered correctly in the ASP Table

CSCvc52504

ASA may traceback with Thread Name: Unicorn Admin Handler

CSCvc52879

Reloading Active unit in Active/Standby ASA failover pair is not triggering a failover.

CSCvc55974

ikev2 handles get leaked in a L2L setup

CSCvc60964

ASA L3 Cluster: DHCP relay drops DHCPOFFER in case of asymmetric routing

CSCvc62252

Tracking route is up while the reachability is down

CSCvc62556

Traceback in ASA Cluster Thread Name: qos_metric_daemon

CSCvc65409

Traceback observed on gtpv2_process_msg on cluster

 

 

Revision:  Version 9.6(2)7 – 12/09/2016

Files:  asa962-7-smp-k8.bin

Defects resolved since 9.6(2)3:

 

CSCtz88975

IPv6 ACLs can be bypassed with crafted packets

CSCuq80704

ASA classifies TCP packets as PAWS failure incorrectly

CSCuu50708

ASA Traceback on 9.1.5.19

CSCuw95262

After some time flash operations fail and configuration can not be saved

CSCuy43438

L2TP over IPSec can not be connected after disconnection from client.

CSCuy89288

AnyConnect DTLS on-demand DPDs are not sent intermittently

CSCuz86289

USGv6 Cert: Non-RH0 Packets Being Dropped w/Valid Policy-Map

CSCva10054

ASA ASSERT traceback in DATAPATH due to sctp inspection

CSCva38556

Cisco ASA Input Validation File Injection Vulnerability

CSCva39094

ASA traceback in CLI thread while making MPF changes

CSCva43992

IKEv2 RA cert auth. Unable to allocate new session. Max sessions reached

CSCva86626

HTML5: Guacamole server requires page refresh

CSCva92813

ASA Cluster DHCP Relay doesn't forward the server replies to the client

CSCvb05667

H.323 inspection causes Traceback in Thread Name: CP Processing

CSCvb13690

ASA : Botnet update fails with a lot of Errors

CSCvb20256

Sweet32 Vulnerability in ASA's SSH Implementation

CSCvb22435

ASA Traceback in thread name CP Processing due to DCERPC inspection

CSCvb29688

Stale VPN Context entries cause ASA to stop encrypting traffic despite fix for CSCup37416

CSCvb45039

ASA traceback with Thread Name aaa_shim_thread

CSCvb49445

IKEv2: It is NOT cleaning the sessions after disconnected from the client.

CSCvb50750

Lina core during failover with sip traffic

CSCvb52988

ASA Traceback Thread Name: emweb/https

CSCvb55721

GARP flood done by ASAs in multi-site cluster using the site-ip address

CSCvb61056

9.6.2 TCP connection doesn't work through L2TP

CSCvb63503

AAA session handle leak with IKEv2 when denied due to time range

CSCvb63819

ASA-SM traceback with Thread : fover_parse during upgrade OS 9.1.6 to 9.4.3

CSCvb64161

ASA fairly infrequently rewrites the dest MAC address of multicast packet for client

CSCvb74084

SCP fails in 962

CSCvb79208

ASA9.(6)1 regression "internal error' instead of "admin disconnect"

 

 

Revision:  Version 9.6(2)3 – 11/01/2016

Files:  asa962-3-smp-k8.bin

Defects resolved since 9.6(2)2:

 

CSCvb36421

v1 handoff gtp stat count incremented for v2-v1 Handoff scenario.

CSCvb41097

GTPv2 Dropping instance 1 handoffs

CSCvb49264

Delete Bearer Req fails to delete second default bearer after v2 Handoff callflow.

CSCvb83446

v1 PDP may get deleted on parse IE failure

 

 

Revision:  Version 9.6(2)2 – 10/24/2016

Files:  asa962-2-smp-k8.bin

Defects resolved since 9.6(2)1:

 

CSCuy47545

http config missing in multicontext after reload of stdby 916.9 or later

CSCuz94890

ASAv ACKs FIN before all data is received during smart licensing exch

CSCva00190

ASA 9.4.2.6 High CPU due to CTM message handler due to chip resets

CSCva35990

Traceback on CP Process with H323 inspection, rip h323_service_early_msg

CSCva52514

ASAv-Azure: waagent may reload when asav deployed with load balancer

CSCva60283

Two Upstream Kernel Patches for ASAv in Azure

CSCva66278

SmartLic: Inter-chassis master switchover license race condition

CSCva70095

ASA negotiates TLS1.2 when server in tls-proxy

CSCva77178

EIGRP does not populate routing table on FPR4K with ASA software

CSCva85382

ASA memory leak for CTS SGT mappings

CSCva90419

issuer-name falsely detecting duplicates in certificate map using attr

CSCva94702

Enqueue failures on DP-CP queue may stall inspected TCP connection

CSCva95686

FTD: 9k byte block depletion leads to dropped traffic

CSCvb21922

Remove ACL warning messages in show access-list when FQDN is unresolved

CSCvb27868

ASA 1550 block depletion with multi-context transparent firewall

CSCvb29411

AAA authentication/authorization fails if only accessible via mgmt vrf

CSCvb30445

ASA may generate DATAPATH Traceback with policy-based routing enabled

CSCvb31833

Traceback : ASA with Threadname: DATAPATH-0-1790

CSCvb32297

WebVPN:VNC plugin:Java:Connection reset by peer: socket write error

CSCvb32341

ASA traceback with passive-interface default on 9.6(2)

CSCvb36199

Thread Name: snmp ASA5585-SSP-2 running 9.6.2 traceback

CSCvb39147

Lower NFS throughput rate on Cisco ASA platform

 

 

Revision:  Version 9.6(2)1 – 09/22/2016

Files:  asa962-1-smp-k8.bin

Defects resolved since 9.6(2):

 

CSCub34054

L2 Clustering:OSPFv2, Eigrp and OSPFv3 RIB not replicated to slave node

CSCum74032

ASA traceback on standby when SNMP polling

CSCux17527

ASA memory leak related to Botnet

CSCux92157

ASA Traceback Assert in Thread Name: ssh_init with component ssh

CSCuz09255

ASA does not respond to NS in Active/Active HA

CSCuz44968

Commands not installed on Standby due to parser switch

CSCuz47295

Cisco ASA Software Local Certificate Authority Denial of Service Vulnerability

CSCuz80281

IPv6 neighbor discovery packet processing behavior

CSCuz92074

ASA with PAT fails to untranslate SIP Via field that doesnt contain port

CSCva02817

ASA not rate limiting with DSCP bit set from the Server

CSCva03607

show service-policy output reporting incorrect values

CSCva05513

ASA: SLA Monitor not working with floating timeout configured to nonzero

CSCva15911

On reloading the ASA, ASA mounts SSD as disk 0, instead of the flash.

CSCva16471

IPv6 OSPF routes do not update when a lower metric route is advertised

CSCva24799

TLS Proxy feature missing client trust-point command

CSCva31378

ASA crash at Thread Name: rtcli async executor process

CSCva36202

BGP Socket not open in ASA after reload

CSCva36884

Cisco ASA Cross Site Scripting SSLVPN Vulnerability

CSCva46920

Traceback in Thread Name: ssh when issuing show tls-proxy session detail

CSCva49256

memory leak in ssh

CSCva68364

SNMPv3 active engineID is not reset when ASA is replaced

CSCva68987

ASA drops ICMP request packets when ICMP inspection is disabled

CSCva69584

OSPF generates Type-5 LSA with incorrect mask, which gets stuck in LSDB

CSCva69799

ASA stuck in boot loop due to FIPS Self-Test failure

CSCva77852

ipsecvpn-ikev2_oth: 5525 9.4.2.11 traceback in Thread Name: IKEv2 Daemon

CSCva84625

ASAv show hostname generates smart licensing authorization request

CSCva84635

ASA: CHILD_SA collision brings down IKEv2 SA

CSCva85933

FTD - 6.1 - redistribute connected is redistributing Internal-Data (NLP)

CSCva87160

OTP authentication is not working for clientless ssl vpn

CSCva90806

ASA Traceback when issue 'show asp table classify domain permit'

CSCva91420

ASA Traceback in CTM Message Handler

CSCvb04685

Unable to delete the SNMP config

CSCvb14664

ASA traceback in ipsecvpn-crypto

CSCvb14997

ASA DHCP Relay rewrites netmask and gw received as part of DHCP Offer

CSCvb19251

ASA as DHCP relay drops DHCP 150 Inform message

CSCvb19843

 

Buffer Overflow in ASA Leads to Remote Code Execution