Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 8.3.2(42) – 10/08/2014

Files:  asa832-42-k8.bin, asa832-42-smp-k8.bin

Defects resolved since 8.3.2(41):

 

CSCum00556

Cisco ASA HPM Denial of Service Vulnerability

CSCum46027

Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability

CSCun11074

Cisco ASA SunRPC Inspection Denial of Service Vulnerability

CSCup36829

Cisco ASA SSL VPN Portal Customization Integrity Vulnerability

CSCuq28582

Cisco ASA VPN Failover Commands Injection Vulnerability

CSCuq29136

Cisco ASA SSL VPN Info Disclosure and DoS Vulnerability

 

 

Revision:  Version 8.3.2(41) – 07/11/2014

Files:  asa832-41-k8.bin, asa832-41-smp-k8.bin

Defects resolved since 8.3.2(40):

 

CSCup22532

Multiple Vulnerabilities in OpenSSL - June 2014

 

 

Revision:  Version 8.3.2(40) – 04/09/2014

Files:  asa832-40-k8.bin, asa832-40-smp-k8.bin

Defects resolved since 8.3.2(39):

 

CSCua85555

Cookie usage in SSL VPN

CSCub38407

Add text section to coredump

CSCul70099

ASA SSL VPN Privilege Escalation Vulnerability

 

 

Revision:  Version 8.3.2(39) – 10/09/2013

Files:  asa832-39-k8.bin, asa832-39-smp-k8.bin

Defects resolved since 8.3.2(37):

 

CSCua22709

ASA traceback in Unicorn Proxy Thread while processing lua

CSCub98434

ASA - SQL*Net Inspection Engine Denial of Service Vulnerability

CSCud37992

HTTP Deep Packet Inspection Denial of Service Vulnerability

CSCug03975

ASA DNS Inspection Denial of Service Vulnerability

CSCug34469

ASA OSPF LSA Injection Vulnerability

CSCug83401

ASA Remote Access VPN Authentication Bypass Vulnerability

CSCuh44815

ASA Digital Certificate HTTP Authentication Bypass Vulnerability

 

 

Revision:  Version 8.3.2(37) – 03/14/2013

Files:  asa832-37-k8.bin, asa832-37-smp-k8.bin

Defects resolved since 8.3.2(34):

 

 

CSCub85692

ASA traceback in IKE Daemon while handling IKEv1 message

 

CSCuc72408

ASA 5580 page fault in thread CERT API during pki validation

CSCud16590

ASA may traceback in thread emweb/https

CSCud89974

flash in ASA5505 got corrupted

 

 

Revision:  Version 8.3.2(34) – 10/10/2012

Files:  asa832-34-k8.bin, asa832-34-smp-k8.bin

Defects resolved since 8.3.2(33):

 

CSCtw84068

DHCP Memory Allocation Denial of Service Vulnerability

CSCtz04566

SSL VPN Authentication Denial of Service Vulnerability

 

 

Revision:  Version 8.3.2(33) – 03/14/2012

Files:  asa832-33-k8.bin, asa832-33-smp-k8.bin

Defects resolved since 8.3.2(25):

 

CSCsv94848

Warning message for, "igmp static-group" - affective should be effective

CSCsy68961

ASA 5580 reboots with traceback in threat detection

CSCsz04730

PIX/ASA: When route changes connections over IPSEC tunnel not torn down

CSCtg06320

DHCP ACK not sent by the firewall.

CSCth40316

Unable to edit the privilege level for cmd object & object-group in 8.3

CSCth70504

Traceback in t_match compile

CSCth77370

IPv6 : ASA Stops responding to IPv6 ND sollicitation

CSCtj09979

IKEv2 traceback with 1 L2L and  1 RA tunnel

CSCtj45148

ASA 8.3 upgrade traceback in thread pix_flash_config_thread

CSCtj79795

WebVPN:flv file within the Flowplayer object is not played over webvpn

CSCtk08509

L2 table entries for identity i/f not deleted when interface removed

CSCtk84288

Syslog %ASA-7-108006 generated erroneously

CSCtn00318

ASA Unexpectedly Reloads with a Traceback due to a Watchdog Failure

CSCtn20148

EIGRP default-route is not displayed w/ "ip default-route" route removed

CSCto08497

ASA: dynamic-filter database update may trigger cpu-hogs

CSCto34765

ASA may traceback in Thread Name: DATAPATH-1-1235 (ipsecvpn-crypto)

CSCto73569

ASA WebVPN clientless not possible to access ipv6 services on the inside

CSCto81636

IPv6 traffic not updated after neighbor changes

CSCtq15197

WebVPN:flv file within the Flowplayer object is not mangled correctly

CSCtq27873

AC can not connect to the ASA if the no. of group aliases is >190

CSCtq34233

ASA traceback in thread emweb/https

CSCtq37772

asa 8.2(2) traceback with TN : Unicorn Proxy Thread

CSCtq57752

ASA: IPSec outbound SA data lifetime rekey fails

CSCtq65262

ASA: SSH sessions return extra characters when using CR+LF

CSCtq75817

Oracle Jinitiator over WebVPN sends incorrect HTTP request

CSCtq84364

High CPU and Orphaned SSH session for on ASA 8.3(2.8)

CSCtq86859

Traceback in Thread Name: IP SLA Mon Event Processor

CSCtq96616

ASA - LU allocate connection failed with conn-max policy

CSCtq97430

Coverity 100595: FORWARD_NULL in ppp_auth_process_attributes()

CSCtr00526

L2TP over IPSec session fails after IPSec P2 rekey

CSCtr03453

Zimbra email suite not usable through WebVPN

CSCtr23854

traceback in Crypto CA during multiple ocsp requests

CSCtr31788

Standby ASA generates syslog 210005 while transmitting data on FTP

CSCtr63728

ASA reloads with traceback in Thread Name : Dispatch Unit

CSCtr66582

Memory leak on ASA 5585-increase of 1% everyday

CSCtr69771

backslash in username for ftp over webvpn changed to semi-colon

CSCtr72514

ASA: Traceback in telnet/ci thread when running 'show webvpn svc'

CSCtr78703

ASA 8.4.2 http inspection might break certain flows intermittently

CSCtr80605

ASA5580 traceback with Thread name telnet/ci

CSCtr91981

LDAP authentication fails when no RootDSE info returned

CSCtr93086

ASA Failover: 106017 Deny IP due to Land Attack on Normal(Waiting) ifc

CSCtr94429

ASA: Local-host and all conns are torn down when client hits conn limit

CSCtr99598

ASA doesn't classify MIME type correctly for .exe and .dmg in Firefox

CSCts07069

ASA: Packet classifier fails with 'any' in Object NAT rule

CSCts09257

Traceback in sch_dispatcher thread

CSCts10661

SSM-4GE doesn't handle unicast packets after "hw-module module 1 reset"

CSCts10797

Webvpn :Support for XFRAME: DENY option in portal

CSCts10887

ASA sends Server Identifier field in DHCP REQUESTS duirng renewal

CSCts13848

ASA may traceback in dns_process

CSCts14130

100% CPU Object Group Search under low traffic due to spin_lock

CSCts15920

ASA: WCCP with authentication fails in 8.3 and 8.4

CSCts18026

ASA 5520 8.2.5 : traceback at thread name snmp

CSCts18480

ASA IKEv1 Traceback in vpnfol_thread_msg ike_fo_create_new_sa on Standby

CSCts32313

ASA 8.4(1) - mailto for xmpp protocol mail clients fails

CSCts32474

Incorrect time displayed on cut through proxy auth page

CSCts33551

NAT-T compatibility improvement with Windows 7

CSCts41215

NAC Framework - Status Query triggers full Posture Revalidation

CSCts42362

Message from ASA is not displayed about password complexity requirements

CSCts43136

ESMTP drops email with DKIM header

CSCts45638

8.4.2.2: Thread Name: DATAPATH-0-1272 Page fault: Unknown

CSCts46366

Slow memory leak by skinny

CSCts48937

Memory leak in DP udp host logging resulting in 1550 byte blocks leak

CSCts52885

Unexpected packet denials during large ACL compilation

CSCts54522

Inspect PPTP does not change CALL-id for inbound Set-Link-Info Packet

CSCts64849

ASA: 8.3/8.4 no longer logs %ASA-3-713167 syslog for rejected user

CSCts69531

Traceback in Dispatch Unit on Standby with timeout floating-conn

CSCts76258

xlate objects with no associated conns and idle timer >  timeout

CSCtt02123

WebVPN: Multiple tracebacks seen in WebVPN in Unicorn Proxy thread

CSCtt02413

DCERPC inspection does not properly fix up port and IP in Map Response

CSCtt03480

ASA Radius User-Password attribute is not included in Access-Request

CSCtt03492

ASA should not send data in the 3rd message of TCP 3WHS w/ LDAP over SSL

CSCtt04614

webvpn - ES keyboard diacritics incorrectly managed by RDP plugin

CSCtt04665

Traceback in Thread Name: IP Address Assign

CSCtt07749

ASA is responding to IKE request when in vpnclient mode

CSCtt11835

Traceback in Thread Name: tacplus_snd

CSCtt13455

netflow: template only send once with default timeout-rate

CSCtt17328

Nested Checkheaps traceback w/ domain-lookup & dynamic-filter blacklist

CSCtt18185

ASA traceback cause by Global Policy

CSCtt19760

ASA may traceback in a DATAPATH thread

CSCtt25173

ASA 5520 8.2.5 memory leak in the inspect/gtp area

CSCtt27599

Standby Firewall traceback citing nat_remove_policy_from_np+383

CSCtt29654

Outbound IPsec traffic interruption after successful Phase2 rekey

CSCtt29810

AAA Command Authorization Reactivates Failed Server on Every Attempt

CSCtt34959

ASA and apple L2TP IPSec client disconnects

CSCtt45496

ASA traceback in thread ci/console with names > 48 char in prefix-list

CSCtt74695

wrong vpn-filter gets applied when peers have overlapping address space

CSCtt76391

SNMPv3 Information Disclosure Vulnerability

CSCtt96550

ASA - Dispatch unit traceback - snp_nat_xlate_timeout

CSCtu00961

Some specific flash file doesn't work through WebVPN on ASA

CSCtu01307

WebVPN: Oracle Java applets failing thru the rewriter

CSCtu04723

vpnclient mac-exempt cmd inconsistent when adding more than 16 entries

CSCtu10620

WebVPN:flv file within the Flowplayer object is not played over webvpn

CSCtu22108

ASA traceback in thread sch_dispatcher when attempting to call home

CSCtu25253

'show shared license' after toggle license-server causes traceback

CSCtu26615

Clientless VPN paging application failure

CSCtu27846

Backup Shared license server remains ACTIVE even when the Master is up

CSCtu30581

ASA 5580 traceback when CSM attempts deployment

CSCtu33068

WebVPN URL Mangler does not handle encoded value of "&#47"

CSCtu40752

5580: assert failure in thread CP Processing

CSCtu42772

ASA webvpn doesn't rewrite some redirect messages properly

CSCtu57453

ASA: Traceback after removing 'ip address dhcp setroute' with DDNS

CSCtv19046

DACL is not applied to AC when connection via the webportal

CSCtw35765

Threat Detection Denial Of Service Vulnerability

CSCtw45576

TCP sequence space check ignored in some cases

CSCtw45723

WebVPN: CIFS: Incorrect MIME type for PDF files - iPad/iPhone

CSCtw56859

Natted traffic not getting encrypted after reconfiguring the crypto ACL

CSCtw58640

When ASA sends a username with a "\", WSA logs errors.

CSCtw58682

SSLVPN Portal uses incorrect DNS Group after failover

CSCtw58945

L2TP over IPSec connections fail with ldap authorization and mschapv2

CSCtw63996

Page fault traceback with thread name "pix_flash_config_thread".

CSCtw81408

Apple Lion OS L2TP Client behind NAT device does not connect

CSCtw89522

Cut-through proxy - users unable to log in

CSCtw93059

Page fault traceback in crypto_lib_keypair_show_mypubkey_all

CSCtw98519

Outbound IPsec traffic interruption after successful Phase2 rekey

CSCtx01251

ASA: May traceback in DATAPATH during capture

CSCtx03464

Standby ASA traceback in DATAPATH-0-1400 or Dispatch Unit

CSCtx08354

Traceback when memory low and memory profile enabled

CSCtx10196

Webvpn : Javascript rewrite causing login button to be inactive

CSCtx11578

ASA does not start DPD when phase 1 up but phase 2 down

CSCtx36026

VPN session failure due to auth handle depletion

CSCtx42643

Received unexpected event EV_REMOVE in state AM_WAIT_DELETE

CSCtx58556

ActiveX RDP Plugin fails to connect from WIn7 PC after upgrade to 8.4(3)

CSCtx69018

MSFT KB2585542 breaks cut-thru proxy and IUA

CSCty31392

RDP activex portforwarder is sometimes not loading

 

 

Revision:  Version 8.3.2(25) – 08/31/2011

Files:  asa832-25-k8.bin, asa832-25-smp-k8.bin

Defects resolved since 8.3.2(13):

 

CSCsg26647

CS: undebug all command doesn't disable debug crypto ca server

CSCsx64778

show memory in a context shows incorrect memory usage

CSCsy93944

Traceback on ACL modify: assertion "status" at "stride_terminal_node.c"

CSCtd73901

Linkdown, Coldstart SNMP Traps not sent with certain snmp-server config

CSCte08816

ASA NAT: LU allocate xlate failed error

CSCte76002

Low performance over shared vlans in multi-mode

CSCte90946

Multi-context ASA Resets a connection from Flooded packet

CSCtf51346

ASA may leave connection in half-closed state

CSCtg06320

DHCP ACK not sent by the firewall.

CSCtg76404

Traceback in Thread Name: Checkheaps due to logging

CSCth05467

WebVPN: Any email can't be sent in OWA 2010 with S/MIME installed

CSCth08965

WebVPN: Bad performance on Internet Explorer 8 for OWA 2010 Premium

CSCth14248

ASA not sending all logging messages via TCP logging

CSCth34278

Clientless WebVPN Memory Leak Causes Blank Page after Authentication

CSCth35961

WebVPN: Preview mode for emails works improperly for DWA 8.5.1

CSCth37641

Write Mem on active ASA 8.3 produces log 742004 on standby

CSCth48476

ASA WebVPN doesnt rewrite URL Encoded Data in Location Response Header

CSCth58048

Assert Failure caused Traceback in Thread Name: Dispatch Unit

CSCth84519

PIM packet with own source address seen after failover on standby peer

CSCti10186

ASA 8.0.5.9  with a traceback in Thread Name:Checkheaps

CSCti11757

SNMP: ASA responds after two SNMP requests

CSCti16604

ASA fails to  delete an existing object in object-group

CSCti34213

The file name is garbled as downloading through SSLVPN and CIFS.

CSCti54387

ASA 8.2.2.x traceback in Thread Name: Dispatch Unit

CSCti54545

EIGRP metrics will not update properly on ASA

CSCti62667

Connections stay open w/ 'sysopt connection timewait' & NetFlow

CSCti88463

WebVPN: Empty emails content for OWA 2010 through Firefox

CSCti96405

ASDM doesn't back up certificate files - indicates that it does

CSCtj11690

Packet-tracer not working in Multi Routed mode

CSCtj16627

DAP:Control access of AnyConnect Apple iOS Mobile without CSD

CSCtj41730

WebVPN: Function "get_base_path" give an error for empty urls

CSCtj45688

ASA: SYN may change close-wait conn to SYN state

CSCtj47335

Problems with Intranet Page displaying when defined as Home Page w/ASA

CSCtj50580

ASA - VPN outbound traffic stalling intermittently after phase 2 rekey

CSCtj55822

ASA webvpn; certain ASP elements may fail to load/display properly

CSCtj77909

ASA:  multiple rules in Name Contraints certificate extension fails

CSCtj78200

certificate name contraints parsing fails when encoding is IA5String

CSCtj78425

Customers Application HQMS being broken by Webvpn Rewriter

CSCtj79795

WebVPN:flv file within the Flowplayer object is not played over webvpn

CSCtj83995

ASA - no names applied to the config when refreshing the config on ASDM

CSCtk04293

Webvpn, SSO with Radius, CSCO_WEBVPN_PASSWORD rewritten with OTP, 8.3

CSCtk10185

OWA login page strip "\" from "domain\username"

CSCtk34526

SSH processes stuck in ssh_init state

CSCtk61443

OpenSSL Ciphersuite Downgrade and J-PAKE Issues

CSCtk84716

IKE proposal for L2TP over IPSec global IKE entry match is duplicated

CSCtk93754

Change in Layered Object Group Does Not Update NAT Table

CSCtk95435

ASA rewriter: radcontrols based AJAX/ASP website not working properly

CSCtl05205

Error entering object group with similar name as network object

CSCtl06156

NAT Xlate idle timer doesn't reset with Conn.

CSCtl09314

"clear conn" behaviour is inconsistent with "show conn"

CSCtl10877

ASA reload in thread name rtcli when removing a plugin

CSCtl67486

ASA MSN Inspection Watchdog Crash

CSCtl17877

SSL handshake - no certificate for uauth users after 8.2.3 upgrade

CSCtl18462

ASA not posting correct link with Protegent Surveillance application

CSCtl18814

UTC time not shown when clock set through user configuration

CSCtl20963

DAP ACL in L2TP doesn't get applied after successful connection

CSCtl20966

The javascript is truncated when accessing via WebVPN portan on ASA

CSCtl21765

Cut-through Proxy - Inactive users unable to log out

CSCtl23397

ASA may log negative values for Per-client conn limit exceeded messg

CSCtl41335

ASA traceback when layer-2 adjacent TCP syslog server is unavailable

CSCtl51919

ASA 8.3 with Static NAT - passes traffic with translated IP in the acl

CSCtl54976

Redundant switchover occurs simultaneously on failover pair

CSCtl56719

Default "username-from-certificate CN OU" doesn't work after reload

CSCtl57784

ASA TCP sending window 700B causing CSM deployment over WAN slow

CSCtl58069

ASA - Traceback in thread DATAPATH-6-1330

CSCtl66155

Invalid internal Phone Proxy trustpoint names generated by imported CTL

CSCtl66339

Traceback in DATAPATH-2-1361, eip snp_fp_punt_block_free_cleanup

CSCtl72355

ASA WEBVPN: POST plugin - Can not find server  .plugins.   or DNS error

CSCtl74435

VPN ports not removed from PAT pool

CSCtl87114

'show mem' reports erroneous usage in a virtual context

CSCtl93641

ASA: Traceback in fover_parse thread after making NAT changes

CSCtl95958

Timeout needs twice time of configured timeout for LDAP in aaa-server

CSCtn01794

IPv6 ping fails when ping command includes interface name.

CSCtn02684

ASA SAP purchasing app may display incorrectly over webvpn

CSCtn07431

L2L IPv6 tunnel with failover not supported Syslog Broken

CSCtn08326

ESMTP Inspection Incorrectly Detects End of Data

CSCtn09117

ASA 8.2.4 402126: CRYPTO: The ASA created Crypto Archive File

CSCtn11061

ASA 5520 traceback in thread emweb/https

CSCtn11423

Traceback in SSH due to ACL

CSCtn25702

URLs in Hidden Input Fields not Rewritten Across WebVPN

CSCtn38584

the packet is discarded when the specific xlate is exist.

CSCtn40210

FTP transfer fails on Standby ASA - uses wrong IP add. in PORT command

CSCtn41118

ASA fails over under intensive single-flow traffic

CSCtn42704

One-to-many NAT with "any" interface not working with PPTP and FTP

CSCtn48877

Traceback in fover_FSM_thread with IPv6 failover on SSM-4GE-INC

CSCtn53896

ASA: police command with exceed-action permit will not replicate to Stby

CSCtn57080

Bookmark macro in post parameters is not replaced with correct user/pass

CSCtn61148

ASA stops handling ikev2 sessions after some time

CSCtn65995

ASA(8.3) adds a trailing space to the object name and the description

CSCtn66992

egress ACL packet drops erroneously counted on ingress interface

CSCtn69941

VPN ports not removed from PAT pool (UDP cases)

CSCtn70741

correct error msg be displayed instead of "ERROR: % Invalid Hostname"

CSCtn74485

ASA5580 traceback in DATAPATH-7-1353

CSCtn74649

BTF DNS-Snooping TTL maxes out at 24 hours, less than actual TTL

CSCtn74652

Search query timeout/errors in SAP purchasing portal via clientless

CSCtn75476

ASA Traceback in Thread Name: snmp

CSCtn79449

Traceback: Thread Name: DATAPATH-3-1276

CSCtn80920

LDAP Authorization doesn't block AccountExpired VPN RA user session

CSCtn84047

ASA: override-account-disable does not work without password-management

CSCtn84312

AnyConnect DTLS Handshake failure during rekey causes packet loss

CSCtn89300

ASA: Memory leak in PKI CRL

CSCtn93052

WebVPN: Office WebApps don't work for SharePoint 2010 in IE

CSCtn96841

"ip local pool" incorrectly rejected due to overlap with existing NAT

CSCtn99124

Dynamic Filter DNS Snooping Database size too small

CSCtn99416

WebVPN: Dropdown menu doesn't work in customized SharePoint 2010

CSCtn99847

Easy VPN authentication may consume AAA resources over time

CSCto05036

DTLS handshake fails on ASA when client retransmits ClientHello

CSCto05478

asa traceback on 8.3.2.13 Thread Name: Dispatch Unit

CSCto05640

call-home config auto repopulates after reboot

CSCto06207

ASA 8.4.1 traceback in Thread UserFromCert

CSCto08752

ASA traceback in 8.4.1 with memory failure errors on IKE daemon

CSCto11365

ASA: Ldap attributes not returned for disabled account

CSCto14043

ASA may traceback when using trace feature in capture

CSCto16917

DAP terminate msg not showing for clientless, cert only authentication

CSCto23713

ASA uses a case-sensitive string compare with IBM LDAP server

CSCto31425

ASA: L2TP and NAT-T overhead not included in fragmentation calculation

CSCto34573

ASA: 8.3 upgrade to 8.4, Shared VPN Licensing config lost unable to conf

CSCto34823

multicast packets dropped in the first second after session creation

CSCto40365

Crafted TACACS+ reply considered as successful auth by ASA

CSCto42990

ASA fails to process the OCSP response resulting in the check failure

CSCto43960

FWSM: DCERPC inspection of packet with multiple segments fails

CSCto48254

ASA reset TCP socket when RTP/RTCP arrives before SIP 200 OK using PAT

CSCto49160

can not access cifs folder with japanese character

CSCto49499

HA: Failover LU xmit/rcv statistics is different on Active and Standby

CSCto50936

SAP Portal - Event Tracking Script fails to display correclty

CSCto53199

Traceback with phone-proxy Thread Name: Dispatch Unit

CSCto62660

ASA 8.4.1 traceback in Thread Name: Unicorn Proxy Thread

CSCto76621

FO cluster lic doesnt work if primary reboots while secondary is down

CSCto76775

ASA AC failure due to slow memory leak: "Lua runtime: not enough memory"

CSCto82315

Traceback in Thread Name: gtp ha bulk sync with failover config

CSCto83156

ASA Sequence of ACL changes when changing host IP of object network

CSCto87674

ST not injected in mstsc.exe on 32-bit Win 7 when started through TSWeb

CSCto89607

ASA sends invalid XML when tunnel-group name contains &

CSCto92380

SunRPC inspection DUMP reply crash

CSCto92398

SunRPC inspection credential length crash

CSCtq00144

VPN RA session DAP  processing fails with memberOf from OpenLDAP

CSCtq06062

SunRPC inspection arithmetic overflow in parse_transport_address

CSCtq06065

SunRPC inspection arithmetic overflow in portmap code

CSCtq07658

ASA: Traceback in ci/console on Standby unit

CSCtq10528

Host listed in object group TD shun exception gest shunned

CSCtq10654

Threat-detecton stats showing incorrect output

CSCtq12037

WebVPN : bytes lost in ftp uploading using IE via smart tunnel

CSCtq13070

VPN-Filter Not Applied When AC Initiated Through Weblaunch

CSCtq19611

IPSec  - Error message trying to reserve UDP port in Multicontext mod

CSCtq27530

Java RDP plugin doesn't work with sslv3 on ASAs

CSCtq30094

CSD scan happens for SSL VPN when connecting via group alias

CSCtq31185

CPU Hog found when invoking 'svc image'

CSCtq46808

ASA rebooted unit always become active on failover setup

CSCtq50523

Using non-ASCII chars in interf desc makes the ASA reload with no config

CSCtq52342

OWA 2007 via WebVPN Sessions fail to get notifications of new emails

CSCtq56043

ASA Tracebacks in 'Thread Name: IPv6 ND'

CSCtq57642

Cannot point IPv6 route to a link-local that matches other intf

CSCtq57697

ILS inspection traceback on malformed ILS traffic

CSCtq62572

Webvpn/mus memory leak observed in 8.4.1.63

CSCtq70326

Interface "description" command allows for more than 200 characters.

CSCtq72776

ASA may reload in threadname Dispatch unit

CSCtq79834

ASA traceback due to dcerpc inspection.

CSCtq84759

ASA wont take "ip audit info action alarm" under "crypto ca" subcommand

CSCtq90084

ASA traceback in thread Dispatch Unit

CSCtr12176

L2L - IPSEC Backup- Peer list is not rotated/cycled with dual failure

CSCtr14920

lightview based Modal Elements do not work with webvpn

CSCtr21346

DCERPC Inspection Denial Of Service Vulnerability

CSCtr21359

DCERPC Inspection Buffer Overflow Vulnerability

CSCtr21376

DCERPC Inspection Denial Of Service Vulnerability

CSCtr23914

ASA: Certificate renewal from same CA breaks SSLVPN

CSCtr26724

ASA threat detection does not show multicast sender IP in statistics

CSCtr33228

Traceback in Dispatch Unit when replicating xlates to standby

CSCtr36022

Java AJAX session does not work over SSLVPN

CSCtr39013

ASA - panic traceback when issuing show route interface_name

CSCtr47517

ASA - Reload in Thread Name: PIM IPv4

CSCtr55374

ASA: asr-group in TFW A/A FO doesn't rewrite dst MAC for IP fragments

CSCtr65241

connections are not replicated to standby unit

CSCtr65785

Enabling AC Essentials should logoff webvpn sess automatically

CSCtr74940

Active ASA traceback Thread: DATAPATH-3-1290, rip spin_lock_get_actual

CSCtr96686

Java RDP plugin traceback when using empty user in URL to Win2008 server

CSCsw15355

ASA may traceback when executing packet-tracer via console/ssh/telnet

 

 

 

Revision:  Version 8.3.2(13) – 02/01/2011

Files:  asa832-13-k8.bin, asa832-13-smp-k8.bin

Defects resolved since 8.3.2(4):

 

CSCsw15355

ASA may traceback when executing packet-tracer via console/ssh/telnet

CSCsy19222

Conns should update when using dynamic protocol and floating statics

CSCtb63515

Clientless webvpn on ASA cannot save .html attached file with IE6 OWA

CSCtc12240

Webvpn- rewrite : ASA inserts lang=VBScript incorrectly

CSCtc15442

IXGBE: interface rx queue low count at 0

CSCte55834

sev1 syslog seen after three failed authentication attempts

CSCte79575

ASA: TFW sh fail output shows Normal(waiting) when Sec unit is act

CSCtf01287

SSH to the ASA may fail - ASA may send Reset

CSCtf20547

Cmd authorization fails for certain commands on fallback to LOCAL db

CSCtf23147

ASA/PIX may generate an ACK packet using TTL received by sender

CSCtf99449

Traceback in thread name Dispatch Unit

CSCtg31015

EIGRP bandwidth value listed incorrectly for SFP gig link on SSM-4GE

CSCtg41691

dynamic-filter database update triggers cpu-hog

CSCtg54977

Error message appears on 5505 console when entering "clear isa sa"

CSCtg94369

ASA 8.3 reboots after installing memory upgrade and copying file

CSCtg99798

ASA Traceback in Thread Name: snmp / checkheaps

CSCth08903

WebVPN: "Invalid Canary" error for different options in OWA 2010

CSCth12612

ASA - VPN load balancing is disabled after failover

CSCth26474

Inspection triggers block depletion resulting in traffic failure

CSCth35722

WebVPN CIFS: 'Authentication error', when DFS host is not reachable

CSCth35961

WebVPN: Preview mode for emails works improperly for DWA 8.5.1

CSCth72642

NAT on 8.3 fails during RPF check

CSCth74607

SMTP DATA packet ending with <CRLF>. wrongly considered as end of DATA

CSCth81601

ASA tracebacks in Thread Name: Dispatch Unit

CSCth85185

WebVPN: DWA 8.0.2 will hung up for message forwarding process

CSCth85774

ASA pair (8.3.1) traceback in Thread Name: Dispatch Unit

CSCti00289

ASA (8.3.1.9) traceback in Thread Name: DATAPATH-5-1315

CSCti07859

AC reports 'certificate validation failed' with VPN LB intermittently

CSCti09288

Traceback in Thread Name: lu_rx - gtp_lu_process_pdpmcb_info

CSCti20506

Transparent fw w/ASR group sets dstMAC to other ctx for last ACK for 3WH

CSCti26495

NAT portlist with failover enabled triggers tmatch assert

CSCti26874

Control-plane feature not working for https traffic to-the-box

CSCti30663

TS Web AppSharing stops working across WebVPN in 8.3.2

CSCti34213

The file name is garbled as downloading through SSLVPN and CIFS.

CSCti43193

webvpn-other: assert traceback in Thread Name: Unicorn Proxy Thread

CSCti43763

Management connection fail after multiple tries with SNMP connections.

CSCti49212

interface command on vpn load-balancing should be shown

CSCti56362

ASA/ASDM history shows total SSL VPN sessions for clientless only

CSCti57626

IUA Authentication appears to be broken

CSCti62358

TFW mode regens cert every time 'no ip address' applied to mgmt int

CSCti65237

slow mem leak in ctm_sw_generate_dh_key_pair

CSCti70936

PKI session exhaustion

CSCti72411

ASA 8.2.3 may not accept management connections after failover

CSCti74419

Standby ASA may traceback in IKE Daemon while deleting a tunnel

CSCti76899

rtcli: traceback in rtcli async executor process, eip ci_set_mo

CSCti77545

ASA 5550 8.3.2 traceback in Thread Name: OSPF  Router

CSCti84683

ACL hash incorrect for protocol object

CSCti87144

L2L traffic recovery fails following intermediary traffic disruption

CSCti88676

ASA Captures will not capture any traffic when match icmp6 is used

CSCti89628

ARP table not updated by failover when interface is down on standby

CSCti90767

ASA 5505 may traceback when booting with an AIP SSC card installed

CSCti92851

Deleting group-policy removes auto-signon config in other group-policies

CSCti93910

ASA automatically enables the 'service resetoutside' command

CSCti94480

Orphaned SSH sessions and High CPU

CSCti98855

Traceback in IKE Timekeeper

CSCti99476

Email Proxy leaking 80 block w/ each email sent

CSCtj01814

page fault traceback in IKE Daemon

CSCtj03800

Second L2TP session disconnects first one if NATed to the same public IP

CSCtj09945

Host Scan with Blank OU field in personal cert causes DAP to fail

CSCtj14005

Traceback with thread name netfs_thread_init

CSCtj15898

ASA webvpn "csco_HTML" may be added to form

CSCtj19221

SYSLOG message 106102 needs to show Username for DAP/vpn-filter

CSCtj20691

ASA traceback when using a file management on ASDM

CSCtj25717

CPU Hog in "NIC status poll" when failing over redundant intf members

CSCtj28057

Quitting "show controller"command with 'q' degrades firewall performance

CSCtj29076

ASR trans FW rewrites wrong dst. MAC when FO peers active on same ASA

CSCtj36804

Cut-through proxy sends wrong accounting stop packets

CSCtj37404

Traceback in mmp inspection when connecting using CUMA proxy feature.

CSCtj46900

Last CSD data element is not being loaded into DAP

CSCtj48788

Page fault traceback on standby in QOS metrics during idb_get_ifc_stats

CSCtj58420

Failed to update IPSec failover runtime data on the standby unit

CSCtj60839

WebVPN vmware view does not work after upgrade to  ASA 8.2.3 and 8.3.2

CSCtj62266

ldap-password-management fails if user password contained & (ampersand)

CSCtj68188

Traceback in Thread Name: ldap_client_thread

CSCtj73930

IPSec/TCP fails due to corrupt SYN ACK from ASA when SYN has TCP option

CSCtj77222

WebVPN: ASA fails to save HTTP basic authentication credential

CSCtj78425

Customers Application HQMS being broken by Webvpn Rewriter

CSCtj84665

Primary stays in Failed state while all interfaces are up

CSCtj85005

ASA as  EasyVPN Client failure on WAN IP Change when using 'mac-exempt'

CSCtj86679

"ci/console " traceback when writing large nat config with FO

CSCtj93922

Standby unit sends ARP request with Active MAC during config sync

CSCtj95695

Webvpn: Java-Trustpoint cmd error, doesn't accept MS code-signing cert

CSCtj96108

Group enumeration possible on ASA

CSCtj96230

H225 keepaplive ACK is dropped

CSCtj97800

a space inserted behind video port number after SIP inspect with PAT on

CSCtk00068

Watchdog timeout traceback following "show route"

CSCtk10911

HA replication code stuck - "Unable to sync configuration from Active"

CSCtk12556

timeout command for LDAP in aaa-server section doesn't work

CSCtk12864

Memory leak in occam new arena

CSCtk15258

ASA traceback in Thread Name:radius_rcv_auth

CSCtk15538

IKE Session : Cumulative Tunnel count always shows Zero

CSCtk54282

Webvpn memory pool may report negative values in "% of current" field.

CSCtk61257

ASA locks up port with mus server command

CSCtk62536

WebVPN incorrectly rewrite logout link of Epic app through Firefox

CSCtk63515

MUS debugs are running with no mus configured

CSCtk83521

homepage use-smart-tunnel not working with Firefox on OSX

CSCtk96848

snmpwalk for crasLocalAddress reports: No Such Instance currently exists

CSCtl06889

Failover interface monitoring only works with the first ten interfaces.

CSCtl10398

Traceback in Dispatch Unit due to dcerpc inspection

CSCtl21314

vpn-filter removed incorrectly from ASP table with EzVPN hw clients

 

Revision:  Version 8.3.2(4) – 09/22/2010

Files:  asa832-4-k8.bin, asa832-4-smp-k8.bin

Defects resolved since 8.3.2:

 

CSCeg69627

DHCPD: show binding should display client-id instead of hw address

CSCsk97762

ENH: Allow DCERPC inspect to open pin-holes for WMI queries. non epm map

CSCtc32872

TFW ENH: Management interface should operate in routed mode

CSCtc40183

8.2.1.11 Webvpn not able to show dropdowns items written in javascripts

CSCtd02193

Heap memory head magic verification failed on asdm access

CSCtd71913

WebVPN Application Access page not displayed if AES chosen

CSCtf06303

Citrix plugin error with HTTPBrowserAddress parameter

CSCtf13774

ASA Traceback Thread Name: Dispatch Unit

CSCtf25270

PP: MTA can be replaced with static/dynamic route

CSCtf28466

ASA Fails to assign available addresses from local pool

CSCtf50185

when doing DTLS rekey, AC may get disconnected with reason idle-timeout

CSCtf52903

Wrong url message is generated when access to group-url ended with "/"

CSCtf96635

Removing HTTP server caused page fault traceback

CSCtg09840

debug webvpn response does not generate any output

CSCtg22656

ASA local CA: not redirected to cert download page when user first login

CSCtg41163

ASA:high memory usage seen on ASA version 8.0.x onwards

CSCtg45489

Access List  for L2L "show crypt ipsec sa" blank after FO and rekey

CSCtg65421

CIFS SSO fails with non-ASCII characters in username or password

CSCtg66583

ASA traceback in Thread Name: RIP Send

CSCtg74608

WEBVPN: PDF form button doesn't work with secure link

CSCtg78505

Cannot SSH to ASA after making changes to webvpn portal via ASDM

CSCtg80816

Clientless WebVPN: DWA 8.0.2 fails to forward attachments

CSCtg86810

show run all command causes SSH session hang

CSCtg89586

RTSP is not translating the client-ports correctly

CSCtg90646

ASA - webtype ACLs are not replicated to the standby

CSCth06056

CWA doesn't login with IE 7 and IE8 or render properly with FireFox 3.x

CSCth09546

ASA 8.3 cut-through-proxy behavior change when authenticating to ASA ip

CSCth11779

ASA sends invalid XML when group-alias contains &

CSCth24465

show nat command shows incorrect line numbers for NAT config lines

CSCth28251

ASA:UDP conns not properly reclassified when tunnel bounces

CSCth31814

Changing interface config to dhcp will add AAA cmd and break EasyVPN

CSCth38721

Timer error on console not useful: init with uninitialized master

CSCth42526

ASA:vpn-sessiondb logoff ipaddress <peer> does not clear tunnelled flows

CSCth42839

show conn port functionality change

CSCth43128

ASA WebVPN : Forms don't get saved in CRM due to no pop-up

CSCth46161

Transparent mode ASA does not pass IPv6 Router Advertisement packet

CSCth48178

ha :Watchdog fover_FSM_thread during failover  IPv6 on SSM-4GE-INC

CSCth49826

Traceback in Unicorn Proxy Thread, address not mapped

CSCth56065

DAP_ERROR:...dap_add_csd_data_to_lua: Unable to load Host Scan data:

CSCth60460

"show service-policy inspect <engine>" may leak 16384 bytes per output

CSCth63101

ASA  HTTP response splitting on /+CSCOE+/logon.html

CSCth67419

WebVPN - rewriter inteprets "application/pdf" as generic link

CSCth67506

ST not injected in mstsc.exe on 64-bit Win 7 when started through TSWeb

CSCth68948

Memory not released after EZVPN client with cert fails authentication

CSCth75120

ASA 8.3; vpn db; IP information not consistent with previous versions

CSCth79877

ASA traceback due to memory corruption

CSCth89217

After failover, CPU-hog and send out ND packet using Secondary MAC

CSCth91572

per-client-max and conn-max does not count half-closed connections

CSCth97330

MS-CHAP-Response generated by ASA has incorrect flags (0x11)

CSCti03135

Search using Dojo Toolkit fails across WebVPN with 404 Error

CSCti06385

ASA XSS on /+CSCOE+/portal.html webvpnLang variable

CSCti06749

ASA: Session Cookies not Marked Secure

CSCti07641

APCF code does not interpret HTTP 304 response code correctly

CSCti09672

vpn-access-hours does not work if client authenticated by certificate

CSCti16527

WEBVPN: Copying >2 GB files fails through CIFS

CSCti21427

Webvpn Customization, DfltCustomization form-order XML error

CSCti22636

"failover exec standby" TACACS+ authorization failure

CSCti24787

Traceback: watchdog in tmatch_release_actual with large tmatch tree

CSCti26495

NAT portlist with failover enabled triggers tmatch assert

CSCti34942

Changing configuration on FT INT not possible after disabling failover

CSCti35310

ISAKMP Phase 1 failure from Remote->ASA with default Phase 1 Values

CSCti35966

Traceback Thread Name: IKE Daemon Assert

CSCti37845

ASA - failover - packet loss when hw-mod reset of SSM mod in fail-open

CSCti38496

ASA SIP inspection does not rewrite with interface pat

CSCti39571

re-enter ipv6 enable does not bring back RRI routes

CSCti39588

invalid ipv6 RRI routes remains after crypto acl changes

CSCti41422

VPN-Filter rules not being cleared even after all vpn sessions gone.

CSCti42879

ASA Traceback in thread Dispatch Unit when executing command alias via https

CSCti47991

timed mode does not fallback to LOCAL if all aaa server are FAILED

CSCti57516

ASA traceback when assigning priv level to mode ldap command "map-value"

CSCti57825

ASA L2L VPN Negative packet encapsulation figures

CSCti62191

ASA traceback in Thread Name: emweb/https when DAP has IPv6 acl on it