Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.5(3)9 – 04/11/2017

Files:  asa953-9-smp-k8.bin

Defects resolved since 9.5(3)6:

 

CSCvb48640

Evaluation of pix-asa for Openssl September 2016

CSCvd78303

ARP functions fail after 213 days of uptime, drop with error 'punt-rate-limit-exceeded'

 

 

Revision:  Version 9.5(3)6 – 12/13/2016

Files:  asa953-6-smp-k8.bin

Defects resolved since 9.5(3)2:

 

CSCtz88975

IPv6 ACLs can be bypassed with crafted packets

CSCup37416

Stale VPN Context entries cause ASA to stop encrypting traffic

CSCuq80704

ASA classifies TCP packets as PAWS failure incorrectly

CSCuu50708

ASA Traceback on 9.1.5.19

CSCuy43438

L2TP over IPSec can not be connected after disconnection from client.

CSCuy55468

Unicorn Proxy Thread causing CP contention

CSCuy89288

AnyConnect DTLS on-demand DPDs are not sent intermittently

CSCva10054

ASA ASSERT traceback in DATAPATH due to sctp inspection

CSCva38556

Cisco ASA Input Validation File Injection Vulnerability

CSCva39094

ASA traceback in CLI thread while making MPF changes

CSCva86626

HTML5: Guacamole server requires page refresh

CSCva92813

ASA Cluster DHCP Relay doesn't forward the server replies to the client

CSCvb13690

ASA : Botnet update fails with a lot of Errors

CSCvb29688

Stale VPN Context entries cause ASA to stop encrypting traffic despite fix for CSCup37416

CSCvb39147

Lower NFS throughput rate on Cisco ASA platform

CSCvb45039

ASA traceback with Thread Name aaa_shim_thread

CSCvb63819

ASA-SM traceback with Thread : fover_parse during upgrade OS 9.1.6 to 9.4.3

CSCvb64161

ASA fairly infrequently rewrites the dest MAC address of multicast packet for client

CSCvb74249

ASA dropping traffic with TCP syslog configured in multicontext mode

CSCvc06150

ASA unable to add multiple attribute entries in a certificate map

 

 

Revision:  Version 9.5(3)2 – 11/03/2016

Files:  asa953-2-smp-k8.bin

Defects resolved since 9.5(3)1:

 

CSCum74032

ASA traceback on standby when SNMP polling

CSCuw95262

After some time flash operations fail and configuration can not be saved

CSCux92157

ASA Traceback Assert in Thread Name: ssh_init with component ssh

CSCuy47545

http config missing in multicontext after reload of stdby 916.9 or later

CSCuz09255

ASA does not respond to NS in Active/Active HA

CSCuz44968

Commands not installed on Standby due to parser switch

CSCuz94890

ASAv ACKs FIN before all data is received during smart licensing exch

CSCva00190

ASA 9.4.2.6 High CPU due to CTM message handler due to chip resets

CSCva02817

ASA not rate limiting with DSCP bit set from the Server

CSCva15911

On reloading the ASA, ASA mounts SSD as disk 0, instead of the flash.

CSCva24924

ASA SM on 9300 reloads multi-context over SSH when config-url is entered

CSCva31378

ASA treaceback at Thread Name: rtcli async executor process

CSCva35439

ASA DATAPATH traceback (Cluster)

CSCva36202

BGP Socket not open in ASA after reload

CSCva36884

Cisco ASA Cross Site Scripting SSLVPN Vulnerability

CSCva39094

ASA traceback in CLI thread while making MPF changes

CSCva39804

Interfaces get deleted on SFR during cluster rejoining

CSCva46920

Traceback in Thread Name: ssh when issuing show tls-proxy session detail

CSCva68364

SNMPv3 active engineID is not reset when ASA is replaced

CSCva69799

ASA stuck in boot loop due to FIPS Self-Test failure

CSCva70095

ASA negotiates TLS1.2 when server in tls-proxy

CSCva77852

ipsecvpn-ikev2_oth: 5525 9.4.2.11 traceback in Thread Name: IKEv2 Daemon

CSCva84635

ASA: CHILD_SA collision brings down IKEv2 SA

CSCva85382

ASA memory leak for CTS SGT mappings

CSCva87160

OTP authentication is not working for clientless ssl vpn

CSCva90419

issuer-name falsely detecting duplicates in certificate map using attr

CSCva90806

ASA Traceback when issue 'show asp table classify domain permit'

CSCva91420

ASA Traceback in CTM Message Handler

CSCva94702

Enqueue failures on DP-CP queue may stall inspected TCP connection

CSCvb03994

Traceback in IKE_DBG

CSCvb04685

Unable to delete the SNMP config

CSCvb05667

H.323 inspection causes Traceback in Thread Name: CP Processing

CSCvb14664

ASA traceback in ipsecvpn-crypto

CSCvb14997

ASA DHCP Relay rewrites netmask and gw received as part of DHCP Offer

CSCvb19251

ASA as DHCP relay drops DHCP 150 Inform message

CSCvb21922

Remove ACL warning messages in show access-list when FQDN is unresolved

CSCvb22435

ASA Traceback in thread name CP Processing due to DCERPC inspection

CSCvb27868

ASA 1550 block depletion with multi-context transparent firewall

CSCvb29411

AAA authentication/authorization fails if only accessible via mgmt vrf

CSCvb30445

ASA may generate DATAPATH Traceback with policy-based routing enabled

CSCvb31833

Traceback : ASA with Threadname: DATAPATH-0-1790

CSCvb32297

WebVPN:VNC plugin:Java:Connection reset by peer: socket write error

CSCvb36199

Thread Name: snmp ASA5585-SSP-2 running 9.6.2 traceback

CSCvb49445

IKEv2: It is NOT cleaning the sessions after disconnected from the client.

CSCvb52988

ASA Traceback Thread Name: emweb/https

CSCvb63503

AAA session handle leak with IKEv2 when denied due to time range

 

 

Revision:  Version 9.5(3)1 – 10/19/2016

Files:  asa953-1-smp-k8.bin

Defects resolved since 9.5(3):

 

CSCvb19843

Buffer Overflow in ASA Leads to Remote Code Execution