Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 9.1.2(8) – 09/03/2013

Files:  asa912-8-smp-k8.bin

Defects resolved since 9.1.2:

 

CSCsv41155

reload due to block depletion needs post-event detection mechanism

CSCtg63826

ASA: multicast 80-byte block leak in combination with phone-proxy

CSCtw57080

Protocol Violation does not detect violation from client without a space

CSCua68934

Editing NAT object/objgrp cfg causes 305006 translation creation failure

CSCua69937

Traceback in DATAPATH-1-1143 thread: abort with unknown reason

CSCua98219

Traceback in ci/console during context creation - ssl configuration

CSCub50435

Proxy ARP Generated for Identity NAT Configuration in Transparent Mode

CSCub52207

Nested Traceback from Watchdog in tmatch_release_recursive_locks()

CSCuc00279

ASA doesn't allow reuse of object when pat-pool keyword is configured

CSCuc66362

CP Processing hogs in SMP platform causing failover problems, overruns

CSCud05798

FIPS Self-Test failure,fips_continuous_rng_test [-1:8:0:4:4]

CSCud20080

ASA Allows duplicate xlate-persession config lines

CSCud21312

ASA verify /md5 shows incorrect sum for files

CSCud34973

ASA stops decrypting traffic after phase2 rekey under certain conditions

CSCud50997

ASA IKEv2 fails to accept incoming IKEV2 connections

CSCud76481

ASA 8.6/9.x : Fails to parse symbols in LDAP attribute name

CSCud84290

ASA: Random traceback with HA setup with 9.1.(1)

CSCud98455

ASA: 256 byte blocks depleted when syslog server unreachable across VPN

CSCue11738

ACL migration issues with NAT

CSCue13581

ASA: cpu-hog in uauth_urlb clean causing interface overruns.

CSCue27223

Standby sends proxy neighbor advertisements after failover

CSCue34342

ASA may traceback due to watchdog timer while getting mapped address

CSCue46275

Connections not timing out when the route changes on the ASA

CSCue46386

Cisco ASA Xlates Table Exhaustion Vulnerability

CSCue48432

Mem leak in PKI: crypto_get_DN_DER

CSCue51796

OSPF routes missing for 10 secs when we failover one of ospf neighbour

CSCue60069

ENH: Reload ASA when free memory is low

CSCue62422

Multicast,Broadcast traffic is corrupted on a shared interface on 5585

CSCue67198

Crypto accelerator resets with error code 23

CSCue78836

ASA removes TCP connection prematurely when RPC inspect is active

CSCue88423

ASA traceback in datapath thread with netflow enabled

CSCue90343

ASA 9.0.1 & 9.1.1 - 256 Byte Blocks depletion

CSCue95008

ASA - Threat detection doesn't parse network objects with IP 'range'

CSCue98716

move OSPF from the punt event queue to its own event queue

CSCuf07393

ASA assert traceback during xlate replication in a failover setup

CSCuf27008

Webvpn: Cifs SSO fails first attempt after AD password reset

CSCuf29783

ASA traceback in Thread Name: ci/console after write erase command

CSCuf31253

Floating route takes priority over the OSPF routes after failover

CSCuf31391

ASA failover standby unit keeps reloading while upgrade 8.4.5 to 9.0.1

CSCuf64977

No debug messages when DHCP OFFER packet dropped due to RFC violations

CSCuf67469

ASA sip inspection memory leak in binsize 136

CSCuf68858

ASA: Page fault traceback in dbgtrace when running debug in SSH session

CSCuf71119

Incorrect NAT rules picked up due to divert entries

CSCuf79091

Cisco ASA time-range object may have no effect

CSCuf85295

ASA changes user privilege by vpn tunnel configuration

CSCuf85524

Traceback when NULL pointer was passed to the l2p function

CSCuf90410

ASA LDAPS authorization fails intermittently

CSCuf92320

ASA-CX: Cosmetic parser error "'sw-module cxsc recover configure image"

CSCuf93071

ASA 8.4.4.1 traceback in threadname Datapath

CSCuf93843

No value or incorrect value for SNMP OIDs needed to identify VPN clients

CSCug03975

ASA 9.1(1) Reboot while applying regex dns

CSCug08285

Webvpn: OWA 2010 fails to load when navigating between portal and OWA

CSCug10123

ASA sends ICMP Unreach. thro wrong intf. under certain condn.

CSCug13534

user-identity will not retain group names with spaces on reboot

CSCug23311

cannot access Oracle BI via clentless SSL VPN

CSCug25761

ASA has inefficient memory use  when cumulative AnyConnect session grows

CSCug29809

Anyconnect IKEv2:Truncated/incomplete debugs,missing 3 payloads

CSCug31704

ASA - "Show Memory" Output From Admin Context is Invalid

CSCug33233

ASA Management lost after a few days of uptime

CSCug39080

HA sync configuration stuck -"Unable to sync configuration from Active"

CSCug45645

Standby ASA continues to forward Multicast Traffic after Failover

CSCug45674

ASA : HTTP Conn from the box, broken on enabling TCP-State-Bypass

CSCug51148

Responder uses pre-changed IP address of initiator in IKE negotiation

CSCug53708

Thread Name: Unicorn Proxy Thread

CSCug55657

ASA does not assign MTU to AnyConnect client in case of IKEv2

CSCug55969

ASA uses different mapped ports for SDP media port and RTP stream

CSCug56940

ASA Config Locked by another session prevents error responses.

CSCug58801

ASA upgrade from 8.4 to 9.0 changes context's mode to router

CSCug63063

ASA 9.x: DNS inspection corrupts RFC 2317 PTR query

CSCug64098

ASA 9.1.1-7 traceback with Checkheaps thread

CSCug66457

ASA : "ERROR:Unable to create router process" & routing conf is lost

CSCug71714

DHCPD appends trailing dot to option 12 [hostname] in DHCP ACK

CSCug72498

ASA scansafe redirection drops packets if tcp mss is not set

CSCug74860

Multiple concurrent write commands on ASA may cause failure

CSCug75709

ASA terminates SIP connections prematurely generating syslog FIN timeout

CSCug76763

Cannot login webvpn portal when Passwd mgmt is enabled for Radius server

CSCug77782

ASA5585 - 9.1.1 - Traceback on IKEv2Daemon Thread

CSCug78561

ASA Priority traffic not subject to shaping in Hierarchical QoS

CSCug79778

ASA standby traceback in fover_parse when upgrading to 9.0.2

CSCug82031

ASA traceback in Thread Name: DATAPATH-4-2318

CSCug83036

L2TP/IPSec traffic fails because UDP 1701 is not removed from PAT

CSCug83080

Cross-site scripting vulnerability

CSCug86386

Inconsistent behavior with dACL has syntax error

CSCug87482

webvpn redirection fails when redirection FQDN is same as ASA FQDN

CSCug90225

ASA: EIGRP Route Is Not Updated When Manually Adding Delay on Neighbor

CSCug94308

ASA: "clear config all" does not clear the enable password

CSCug95287

ASA IDFW: idle users not marked as 'inactive' after default idle timeout

CSCug98852

Traceback when using VPN Load balancing feature

CSCug98894

Traceback in Thread Name: OSPF Router during interface removal

CSCuh01167

Unable to display webpage via WebVPN portal, ASA 9.0(2)9

CSCuh01983

ASA tearsdown TCP SIP phone registration conn due to SIP inspection

CSCuh05751

WebVPN configs not synchronized when configured in certain order

CSCuh05791

Single Sign On with BASIC authentication does not work

CSCuh08432

Anyconnect sessions do not connect due to uauth failure

CSCuh08651

UDP ports 500/4500 not reserved from PAT on multicontext ASA for IKEv1

CSCuh09400

ASA OSPF route stuck in database and routing table

CSCuh10827

Cisco ASA config rollback via CSM doesnt work in multi context mode

CSCuh12375

ASA multicontext transparent mode incorrectly handles multicast IPv6

CSCuh13899

ASA protcol inspection connection table fill up DOS Vulnerability

CSCuh14302

quota management-session not working with ASDM

CSCuh19234

Traceback after upgrade from 8.2.5 to 8.4.6

CSCuh19462

ASA 9.1.2 - Memory corruptions in ctm hardware crypto code.

CSCuh20372

ASA adds 'extended' keyword to static manual nat configuration line

CSCuh20716

Re-transmitted FIN not allowed through with sysopt connection timewait

CSCuh22344

ASA: WebVPN rewriter fails to match opening and closing parentheses

CSCuh23347

ASA:Traffic denied 'licensed host limit of 0 exceeded

CSCuh27912

ASA does not obfuscate aaa-server key when timeout is configured.

CSCuh33570

ASA: Watchdog traceback in SSH thread

CSCuh34147

ASA memory leaks 3K bytes each time executing the show tech-support.

CSCuh40372

ASA Round-Robin PAT doesn't work under load

CSCuh45559

ASA: Page fault traceback when changing ASP drop capture buffer size

CSCuh48005

ASA doesn't send NS to stale IPv6 neighbor after failback

CSCuh48577

Slow memory leak on ASA due to SNMP

CSCuh52326

ASA: Service object-group not expanded in show access-list for IDFW ACLs

CSCuh56559

ASA removed from cluster when updating IPS signatures

CSCuh58576

Different SNMPv3 Engine Time and Engine Boots in ASA active / standby

CSCuh66892

ASA: Unable to apply "http redirect <interface_name> 80" for webvpn

CSCuh69818

ASA 9.1.2 traceback in Thread Name ssh

CSCuh69931

ASA 5512 - 9.1.2 Traceback in Thread Name: ssh

CSCuh73195

Tunneled default route is being preferred for Botnet updates from ASA

CSCuh74597

ASA-SM multicast boundary command disappears after write standby

CSCuh78110

Incorrect substitution of  'CSCO_WEBVPN_INTERNAL_PASSWORD' value in SSO

CSCuh79288

ASA 9.1.2 DHCP - Wireless Apple devices are not getting an IP via DHCPD

CSCuh79587

ASA5585 SSM card health displays down in ASA version 9.1.2

CSCuh80522

nat config is missing after csm rollback operation.

CSCuh90799

ASA 5505 Ezvpn Client fails to connect to Load Balance VIP on ASA server

CSCuh94732

Traceback in DATAPATH-1-2533 after a reboot in a clustered environment

CSCuh95321

Not all contexts successfully replicated to standby ASA-SM

CSCui10904

Macro substitution fails on External portal page customization

CSCui13436

ASA-SM can't change firewall mode using session from switch

CSCui15881

ASA Cluster - Loss of CCL link causes clustering to become unstable

CSCui27831

Nested Traceback with No Crashinfo File Recorded on ACL Manipulation

CSCui42956

ASA registers incorrect username for SSHv2 Public Key Authenticated user

CSCui48221

ASA removes RRI-injected route when object-group is used in crypto ACL