Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 9.0(4)42 – 10/19/2016

Files:  asa904-42-smp-k8.bin, asa904-42-k8.bin

Defects resolved since 9.0(4)40:

 

CSCuy54567

Evaluation of pix-asa for OpenSSL March 2016

CSCuy99280

ENH: ASAv should have a different pre-loaded cert

CSCuz47295

Cisco ASA Software Local Certificate Authority Denial of Service Vulnerability

CSCvb19843

Buffer Overflow in ASA Leads to Remote Code Execution

 

 

Revision:  Version 9.0(4)40 – 08/24/2016

Files:  asa904-40-smp-k8.bin, asa904-40-k8.bin

Defects resolved since 9.0(4)39:

 

CSCuz80281

IPv6 neighbor discovery packet processing behavior

CSCva92151

Cisco ASA SNMP Remote Code Execution Vulnerability

 

 

Revision:  Version 9.0(4)39 – 04/08/2016

Files:  asa904-39-smp-k8.bin, asa904-39-k8.bin

Defects resolved since 9.0(4)38:

 

CSCux41145

Evaluation of pix-asa for OpenSSL December 2015 Vulnerabilities

 

 

Revision:  Version 9.0(4)38 – 01/14/2016

Files:  asa904-38-smp-k8.bin, asa904-38-k8.bin

Defects resolved since 9.0(4)37:

 

CSCux29978

Cisco ASA IKEv1 and IKEv2 Buffer Overflow Vulnerability

 

CSCux42019

Cisco ASA IKEv1 and IKEv2 Buffer Overflow Vulnerability

 

 

Revision:  Version 9.0(4)37 – 10/21/2015

Files:  asa904-37-smp-k8.bin, asa904-37-k8.bin

Defects resolved since 9.0(4)35:

 

CSCur45455

ASA crashes in DHCPV6 Relay agent feature Functionality

CSCus46895

WebVPN Rewriter: "parse" method returns curly brace instead of semicolon

CSCus57142

ASA traceback in threadname Checkheaps when it hits dhcpv6 packet

CSCus94026

ISAKMP SERVER traffic from codenomicon crashes ASA

CSCut03495

ASA traceback in ThreadName:ci/console,while pinging DNS Server name

CSCuu07799

Traceback: mem_get_owner+104 at slib/../finesse/snap_api.h:163

CSCuu83280

Evaluation of OpenSSL June 2015

 

 

Revision:  Version 9.0(4)35 – 06/16/2015

Files:  asa904-35-smp-k8.bin, asa904-35-k8.bin

Defects resolved since 9.0(4)33:

 

CSCsj50741

ASA: DHCP relay does not validate the Server Identifier of a reply

CSCtz48533

Cisco ASA Challenge-Response Tunnel Group Selection Bypass Vulnerability

CSCur17006

Add cli to control masked username in syslog

CSCur55388

Usernames obscured with asterisks in logs after upgrade to ASA 9.1(5.16)

CSCus23416

ASA traceback in DATAPATH-1-2414 after software upgrade

CSCus51289

ASA: Traceback when removing manual NAT rule

CSCus63269

HTTP redirect to the VPNLB address using HTTPS fails in 9.1.5

CSCus98250

ASA WEBVPN: Usernames shown as '*' in logs for failed authentication

CSCut46019

MARCH 2015 OpenSSL Vulnerabilities

 

 

Revision:  Version 9.0(4)33 – 04/08/2015

Files:  asa904-33-smp-k8.bin, asa904-33-k8.bin

Defects resolved since 9.0(4)29:

 

CSCuj68919

Multiple problems with output of show processes memory

CSCul02601

ASA Crash in checkheaps due to snmp component

CSCuq57307

ASA 8.4 Memory leak due to duplicate entries in ASP table

CSCuq77655

Cisco ASA DNS Memory Exhaustion Vulnerability

CSCur21069

Cisco ASA Failover Command Injection Vulnerability

CSCur42776

Mac version smart-tunnel uses SSLv3 which is  a vulnerability

CSCur56038

RPC error in request config after replicated a large configuration

CSCur68226

ASA SMTP inspection should not disable TLS by default

CSCur81376

ASA traceback in Thread Name: ci/console, assertion "snp_sp_action.c"

CSCur95551

ASA prefers Suite-B algorithms w/ AC Essentials enabled for AC IKEv2

CSCur99221

NetFlow incorrect reporting for PPTP VPN over GRE

CSCus11465

ASA teardown connection after receiving same direction fins

CSCus53692

ASA traceback in Thread Name: fover_parse

CSCus62884

ASA 9.1.5 does not always drop connections after receiving RST+ACK flag

CSCus64082

ASA fails to sync objects with name ANY after upgrade from 8.4 to 9.x

CSCus76060

ASA clears the TOS value of ICMP echo reply packet from ASA's interface

CSCus83476

More than 255 messages in multicast packet with jumbo frames

CSCus88626

Radius Acct-Terminate-Cause for L2TP over IPSec is incorrect.

CSCus91407

Network Object NAT is not working when config-register == 0x41

CSCus95290

Cisco ASA VPN XML Parser Denial of Service Vulnerability

CSCus98309

Duplicate IPv6 address is configurable in 1 ASA or context

CSCut06531

ASA: XFRAME support for .JS and .JNLP URL's

CSCut19319

BG:EUI-64 configuration not to be enforced for MGMT interface

CSCut22865

[ASA] CTP not working if proxyACL port_argument is gt

CSCut45114

2048-byte block leak if DNS server replies with "No such name"

 

Revision:  Version 9.0(4)29 – 02/03/2015

Files:  asa904-29-smp-k8.bin, asa904-29-k8.bin

Defects resolved since 9.0(4)26:

 

CSCuf67469

ASA SIP Inspection Memory Leak Vulnerability

CSCul61545

ASA Page Fault Traceback in 'vpnfol_thread_msg' Thread

CSCuq59114

ASA traceback in cluster with DATAPATH thread

CSCur17483

nested custom write functions causing blank page through rewriter

CSCur41860

HTTP and FTP Copy operations exposes sensitive information in syslogs

CSCur59704

ASA: Traceback in idfw_proc

CSCur66635

ASA Traceback in Thread Name: DATAPATH-3-1274

CSCur68226

ASA SMTP inspection should not disable TLS by default

CSCur76771

scansafe feature is missing from registered module features

CSCur87061

Potential ICMP error storm in cluster CCL link

CSCur88829

ASA IPSEC client PKI username from certificate authorization failure

CSCur94645

ASA - Additional empty fields in RADIUS Access-Request packet

CSCus03141

ipsec-datapath:TFW management connection via VPN takes a few minutes

CSCus06652

ASA5580-20 8.4.7.23: Traceback in Thread Name: ssh

CSCus08101

ASA: evaluation of Poodle Bites in TLSv1

CSCus14009

ASA WebVPN Citrix SSO: Chrome does not skip to login on external page

CSCus42901

JANUARY 2015 OpenSSL Vulnerabilities

 

 

Revision:  Version 9.0(4)26 – 12/09/2014

Files:  asa904-26-smp-k8.bin, asa904-26-k8.bin

Defects resolved since 9.0(4)24:

 

CSCtt88306

Syslog 106100 not generated on second context when cascading contexts.

CSCtz82865

SNMP MIB: Equivalent of "show xlate count" command

CSCtz98516

Observed Traceback in SNMP while querying GET BULK for 'xlate count'

CSCua45564

Add a CLI to configure SSL FCADB timeout

CSCua66053

Hostscan ASA token times out on slow connections

CSCub53088

Arsenal:twice NAT with service type ftp not working.

CSCuf31607

Linux Kernel Invalid fs and gs Registry KVM Denial of Service Vulnerab

CSCuf31654

Linux Kernel GUID Partition Tables Handling Arbitrary Code Execution V

CSCug51375

ASA SSL: Continues to accept SSLv3 during TLSv1 only mode

CSCui27525

Idle timer and half-closed idle timer reset by out of sequence SYN

CSCul94773

ASA TCP Proxy can corrupt data, cause ACK storms and session hangs

CSCun26772

Invalid user names are logged in syslogs

CSCun43072

ASA5585-SSP60 Traceback in Thread Name SSH on Capture Command

CSCun88736

ASA does not recognise "packet too big" for assembled ICMPv6 echo reply

CSCuo26501

ASA: Traceback in Thread Name: Dispatch Unit when enable debug ppp int

CSCuo45321

ASA allows IKEv1 clients to bypass address assignment, causing conflict

CSCup87430

accounting not per rfc in dual factor auth case

CSCup92782

ASA providing inaccurate Tunnel count to ASDM

CSCuq21016

Local pool address not released -> Duplicate local pool address found

CSCuq36615

Traceback caused by WCCP

CSCuq39567

Traceback in Thread Name qos_metric_daemon caused by asdm history enable

CSCuq60566

Incorrect content-length when maddr present with URI in SIP message body

CSCuq62925

ASA: standby traceback during replication of specific privilege command

CSCuq65201

ASA Local CA generates unexpected renewal reminder message

CSCuq65542

Cisco ASA Software Version Information Disclosure Vulnerability

CSCuq66078

Traceback in clacp_enforce_load_balance with ASA Clustering

CSCuq68271

ASA Cluster slave unit loses default route due to sla monitor

CSCuq68888

Cisco ASA SSL VPN Memory Blocks Exhaustion Vulnerability

CSCuq75981

ASA traceback in DATAPATH-0-2078 thread

CSCuq77228

ASA Cluster: IDFW traceback inThread Name: DATAPATH-3-132

CSCuq78238

Inspect rule defaults in standby transparent context on write standby

CSCuq80639

ASA5580 speed nonegotiate settings kept link down after shut/no shut

CSCuq87632

User membership not updated in parent group

CSCuq91793

ASA: RST packet forwarded with non-zero ACK number (and ACK flag clear)

CSCuq98633

Object Group Search causing legitimate traffic to be dropped by ACL

CSCur02239

ASA ACL hitcount not correct for ACLs with service object groups

CSCur16308

DHCP Relay reloads after changing server interface

CSCur16793

xlate per-session commands are not synchronized

CSCur17329

SDI authentication doesn't work in more than one contexts.

CSCur23709

ASA  : evaluation of SSLv3 POODLE vulnerability

CSCur24059

Control Plane ACL Not Working for Redirected HTTP Traffic

CSCur25431

ASA assert traceback on Standby Unit in c_idfw.c

CSCur25542

Traceback: pki-crl: Thread Name: Crypto CA with traffic through VPN L2L

CSCur27845

ASA Client login timeout issue due to proxy match inconsistency

CSCur28615

Hex code associated with syslog is referenced from the old ACE/ACL

CSCur34960

ASA5585 traceback on Thread name: idfw_proc

CSCur52712

Webvpn: Support for XFRAME for non-critical URL's

CSCur64589

DATAPATH Traceback in snp_mp_svc_udp_upstream_data function

CSCur64659

ASA Traceback in Thread Name: DATAPATH-6-2544

 

 

Revision:  Version 9.0(4)24 – 10/02/2014

Files:  asa904-24-smp-k8.bin, asa904-24-k8.bin

Defects resolved since 9.0(4)20:

 

CSCty17881

vpn-sessiondb detail missing Filter Name after IKEv1 rekey

CSCub05888

Asa 5580-20: object-group-search access-control causes failover problem

CSCue48425

Mem leak in ikev2 tk: ikev2_dupe_id

CSCug25761

ASA has inefficient memory use  when cumulative AnyConnect session grows

CSCuh84378

ASA: Last packet in PCAP capture file not readable

CSCui95392

WebVPN portal page misses large title after portal redesign

CSCul04263

ASA Webvpn CIFS vnode_create: VNODE ALLOCATION LIMIT 100000 REACHED!

CSCul22575

ASA 8.4.6 MAC Address flapping with Port-Channels and IPv6

CSCul37888

traffic does not match time-rang access-list configured with policy-maps

CSCul46971

ASA Transparent mode doesn't pass DHCP discover message

CSCun12838

ASA Traceback in DATAPATH-1-1400 with error message shrlock_join_domain

CSCun23552

XenDeskTop7:cannot relogin to StoreFront ineterface after logoff

CSCun43082

ASA Tears Down Connections With Reason of  'snp_drop_none'

CSCun86984

ASA 5505 u-turned/hairpinned conn counts toward license local-host limit

CSCuo09383

ASA WebVPN Memory leak leading to Blank Portal Page/AnyConnect failure

CSCuo11778

ENH: Add "speed nonegotiate" command for fiber interfaces on ASA5585

CSCuo27866

Traceback on DATAPATH-7-1524 Generating Botnet Filter Syslog

CSCuo48593

ASA with SFP+4GE-SSM sends flow-control packets at line rate

CSCuo53772

CWS: Large downloads on HTTPS fail when server side seq number wraps

CSCuo54393

ASA: HTTP searchPendingOrders.do function failing over WebVPN

CSCuo88253

ASA NAT: Some NAT removed after upgrade from 8.6.1.5 to 9.x

CSCuo91763

ASA allows to empty an access-list referenced elsewhere

CSCuo95074

ASA AnyConnect failure or crash in SSL Client compression with low mem

CSCuo97036

show vpn load-balancing shows Public addr as Cluster IP addr for Master

CSCup00433

Failover Standby unit has higher memory utilization

CSCup07447

ASA WebVPN: Script error when using port-forwarding

CSCup08912

ASA SSLVPN Java plugins fail through proxy with Connection Exception

CSCup08934

ASA WebVPN Rewriter: Custom HTTP Headers Not Properly Rewritten

CSCup13265

ASA - Traceback in thread name: sch_prompt anonymous reporting

CSCup26021

TCP intercept does not work after embryonic connection ends

CSCup26347

ASA Panic: CP Processing - ERROR: shrlock_join_domain

CSCup28968

When ACL optimization is enabled, wrong rules get deleted

CSCup35713

ASA tmatch_summary_alloc block leak in binsize 1024

CSCup36829

Cisco ASA SSL VPN Portal Customization Integrity Vulnerability

 

CSCup40357

SNMP: Unable to verify presence of second power supply in ASA 5545

CSCup43257

ASA Traceback in Thread name: ci/console while modifying an object-group

CSCup46524

"no speed nonegotiate" command in ASA 5580 running 9.1.5 in show run

CSCup48772

ASA - Wrong object-group migration during upgrade from 8.2

CSCup48979

ASA - Permitting/blocking traffic based on wrong IPs in ACL

CSCup50857

ASA traceback in thread name idfw_adagent

CSCup54184

ASA Overwrite any file on WebVPN RAMFS

CSCup55377

ASA: Traceback Page Fault in vpnfol_thread_msg on Standby ASA

CSCup59017

ASA with ACL optimization crashing in "fover_parse" thread

CSCup59774

No syslogs for ASDM or clientless access with blank username/password

CSCup60837

Personal bookmarks get deleted with ASA in Active/Standby failover

CSCup68697

WebVPN: uploading customized portal.css breaks the portal login page

CSCup70720

ASA crashes with Page Fault with multiple configuration sessions

CSCup74532

ASA failover standby device reboots due to delays in config replication

CSCup76212

ASA rewrites incorrect content-length in SIP message

CSCup85529

ASA Smart Call does not hide IPv6 addresses for ND

CSCup86857

IPv4 ACLs not working after merging IPv4 and IPv6 ACLs by upgrading

CSCup86960

ASA : Failover descriptor does not change after reconfiguring VLAN

CSCup95436

WebVPN: sharepoint 2007/2010 and Office2007 can't download/edit pictures

CSCuq03216

IPsecOverNatT tunnel disappears after ASA failovers

CSCuq04306

Smart Tunnels Spawn "UNKNOWN Publisher" Warning w/Java 7 Update 60

CSCuq05768

Using "?" to list files in directory with thousands of files causing hog

CSCuq08854

Show memory app-cache command shows incorrect bytes if more than 2^32

CSCuq09352

vbscript getting caught in loop when passing thru ASA WebVPN Rewriter

CSCuq24404

traceback in thread name: netfs_thread_init

CSCuq26046

ASA - Traceback in thread name SSH while changing NAT configuration

CSCuq28582

Cisco ASA Privilege Escalation

CSCuq28978

WebVPN: Rewriter issue with PATHIX Inspection Database

CSCuq29136

ASA: Entering Query String on /+CSCOE+/logon.html disclose information

CSCuq34213

Double Free when processing DTLS packets

CSCuq34226

OpenSSL Zero-Length Fragments DTLS Memory Leak Denial of Service Vuln

CSCuq38807

ASA Radius Access-Request contains both User-Password and CHAP-Password

CSCuq57188

ASA returns wrong content-length for cut-thru proxy authentication page

 

 

Revision:  Version 9.0(4)20 – 07/22/2014

Files:  asa904-20-smp-k8.bin, asa904-20-k8.bin

Defects resolved since 9.0(4)17:

 

CSCup08262

9.0(4)5 - Unable to access internal site via clientless SSLVPN

CSCup47885

ASA: Page fault traceback in DATAPATH when DNS inspection is enabled

 

 

Revision:  Version 9.0(4)17 – 07/07/2014

Files:  asa904-17-smp-k8.bin, asa904-17-k8.bin

Defects resolved since 9.0(4)7:

 

CSCsk87165

ENH - Add device serial number and platform string to show run output

CSCsz39633

Double auth not triggered if using secondary-aaa-server per interface

CSCtj51276

Implement a syslog to indicate the version of the anyConnect client

CSCtw82904

ESP packet drop due to failed anti-replay checking after HA failovered

CSCub89800

WebVPN: Rich Edit dropdowns doesn't work in SharePoint 2010

CSCub92315

ASA allows SSL trustpoint with 4096 bit keys - SSL fails to work

CSCue38161

wr mem all produces traceback on console

CSCue48441

Mem Leak: ikev2_fo_parse_sa_message_id_data_v1

CSCug51755

ICMP destination unreachable for L2TP PMTU error not sent to server

CSCuh38785

Improve ScanSafe handling of Segment HTTP requests

CSCuh79288

ASA 9.1.2 DHCP - Wireless Apple devices are not getting an IP via DHCPD

CSCui00048

ASA traceback with 'debug menu webvpn 160' command

CSCui48225

AAA: Authentication fails with Double Auth+Password Management on LDAP

CSCuj98221

IDFW: user-group is not deactivated even if IDFW ACL is removed

CSCul22215

Traceback when using IDFW ACL's with VPN crypto maps

CSCul22237

ASA may drop all traffic with Hierarchical priority queuing

CSCul33381

ASA 5505 SIP packets may have extra padding one egress of 5505

CSCul34702

ASA Unicorn rewriter memory corruption

CSCul37888

traffic does not match time-rang access-list configured with policy-maps

CSCul53300

VPNLB syslogs to console missing newline

CSCul55863

ASA with ICMP insp. drops replies with 'seq num not matched' code

CSCul60058

Case sensitivity check missing for Web Type ACL and Access-group

CSCul70062

Capture Isakmp w/ match statement cause Standby to reload at replication

CSCum00360

ASA - DHCP Discover Sent out during boot process

CSCum11724

secondary standby looses his cluster license after upgrade to 8.4.(7.3)

CSCum12633

webvpn issue,part of the http request not sent by the client to ASA

CSCum56003

Smart-tunnel for windows-Liveconnect exception-JRE 1.7u51

CSCum63417

ASA should not allow interface MTU config greater than 9202/9198

CSCum72854

Traffic does not hit Twice NAT configured after Static PAT

CSCum75214

ASA5585-SSP60 Teardown process is delayed under heavy traffic condition

CSCum76734

ASA Backup scansafe tower is never polled

CSCum80899

ASA: Watchdog traceback in Unicorn Admin Handler with TopN host stats

CSCum85047

Traceback in Thread: IPsec message handler with rip-tlog_event_allocate

CSCum86538

SunRPC GETPORT Reply dropped when two active sessions use same xid

CSCum92080

Sourcefire Defense Center not able to be rendered via Clientless SSL VPN

CSCun08017

ASA WebVPN memory leak - blank portal page

CSCun10844

Java rewriting takes too much time

CSCun16022

ASA traceback in Thread Name: IKE Daemon: with CX redirect in place.

CSCun17705

Regex modification within context causes ASA traceback

CSCun19025

ASA WebVPN login page XSS vulnerability

CSCun25809

AnyConnect Password Management Fails with SMS Passcode

CSCun31725

ASA using IKEv2 rejects multiple NAT_DETECTION_SOURCE_IP payloads

CSCun32324

ASA Cluster ICMP with PAT not functional on reload

CSCun32897

Data path: ASA traceback in CTM message handler

CSCun41702

L2TP/IPSec connection is failed when there is PAT router.

CSCun41817

Hash calculated for multiple ACEs on ASA are same

CSCun45520

Cisco ASA DHCPv6 Denial of Service Vulnerability

CSCun59657

ASA-SM not sending SNMP traps with 9.0.4

CSCun61466

terminal width command is deleted when removing other context

CSCun66161

5585-20 8.4.7.11 traceback in Thread Name Datapath w/ DCERPC inspection

CSCun66306

IDM/IME/File Transfer Slow For Certain Source and Destination IP Pairs

CSCun69669

Posture assement failing after HS upgrade to 3.1.05152

CSCun71586

MEMLEAK: 128 byte leaks when requesting IPv6 address for AnyConnect

CSCun75965

Name for IPv6 address causes objects to became empty after reload

CSCun78551

Cisco ASA Information Disclosure Vulnerability

CSCun83186

Nameif command not allowed on TFW multimode ASA with clustering

CSCun85465

'ASA modifies Request Host Part under 'ACK' packet for SIP connection'

CSCun85942

ASA drops DNS PTR Reply w/ reason Label length exceeded during rewrite

CSCun88276

High CPU with IKE daemon Process

CSCun95075

ASA drops packet due to nat-no-xlate-to-pat-pool after removing NAT rule

CSCun96170

ASA 8.4.6: Traceback with fover_FSM_thread

CSCuo00627

Saleen copper module port speed/duplex changes ineffective

CSCuo00904

ASA Page Fault: Invalid Permission in thread name DATAPATH

CSCuo02948

To the box traffic dropped due to vpn load-balancing (mis)configuration

CSCuo03555

SNMP: cpmCPUTotal5sec/1min/5min return "0"

CSCuo03569

VPN client firewall and split-tunneling mishandle "inactive" acl rules

CSCuo09383

ASA WebVPN Memory leak leading to Blank Portal Page/AnyConnect failure

CSCuo10869

VPN-filter ACL drops all traffic after upgrade for pre 8.3 to 9.x

CSCuo11057

IPsec transform sets mode changes from transport to tunnel after editing

CSCuo11867

CSCub92315 fix is incomplete

CSCuo14701

Interop: relax PrintableString encoding enforcement in PKI

CSCuo19916

ASA - Cut Through Proxy sends empty redirect w/ Virtual HTTP and Telnet

CSCuo33186

Traceback with  thread DATAPATH-2-1181

CSCuo46136

ASA does not relay BOOTP packets

CSCuo49385

Multicast - ASA doesn't populate mroutes after failover

CSCuo60435

ASA: Webvpn using incorrect password for auto-signon with Radius/OTP

CSCuo61372

ASA doesn't send invalid SPI notify for non-existent NAT-T IPSec SA

CSCuo63172

ASA 9.1.(3)4  Memory Leak in KCD

CSCuo64803

ASA Rewriter does not support encoded values for characters like " ' "

CSCuo68327

ASA: Traceback in DATAPATH thread related to DNS inspection

CSCuo68521

ASA: Page fault traceback in Dispatch Unit

CSCuo70963

WebVPN: Javascript rewrite issue with Secret Server Application

CSCuo73792

ASA 9.x Management Port-Channel Cannot configure management-only in TFW

CSCuo78892

Traceback when using IDFW ACL's with VPN VPN Filters

CSCuo95602

Standby ASA traceback on Fover_Parse with Botnet Filter

CSCup22532

Multiple Vulnerabilities in OpenSSL - June 2014

 

 

Revision:  Version 9.0(4)7 – 04/18/2014

Files:  asa904-7-smp-k8.bin, asa904-7-k8.bin

Defects resolved since 9.0(4)5:

CSCum70178

Datapath:Observing Deadlock in different DATAPATH threads

CSCum75871

Traceback on standby ASASM when executing the failover active command

CSCuo00904

ASA Page Fault: Invalid Permission in thread name DATAPATH

CSCuo08511

ASA 9.0.4.1 traceback in webvpn datapath

CSCuo27054

Failed to show "extended permit" in show access-list test

 

 

Revision:  Version 9.0(4)5 – 04/09/2014

Files:  asa904-5-smp-k8.bin, asa904-5-k8.bin

Defects resolved since 9.0(4)1:

 

CSCtn30286

DHCP Relay needs to handle DHCPREQUEST differently

CSCua68934

Editing NAT object/objgrp cfg causes 305006 translation creation failure

CSCud24785

Slow throughput of AnyConnect client w/DTLS compared to IPSec IKEv1

CSCug49382

IKEv2 : L2L tunnel fails with error "Duplicate entry in Tunnel Manager"

CSCug87445

SVC_UDP Module is in flow control with a SINGLE DTLS tunnel

CSCuh61321

AC 3.1:ASA incorrectly handles alternate DTLS port,causes reconnect

 

CSCui36033

PP: VoIP interface fails replication on standby due to address overlap

CSCui56863

ASA may reload with traceback in Thread Name: vpnfol_thread_msg

CSCui79979

ASA 9.1.2 - Traceback in Thread Name: fover_parse during configuration

CSCuj10294

CSCul37888Traceback in DATAPATH caused by HTTP Inspection

CSCuj33701

traceback ABORT(-87): strcpy_s: source string too long for dest

CSCuj35576

ASA OSPF route stuck in database and routing table

CSCuj45406

ASA: Page fault traceback with 'show dynamic-filter dns-snoop detail'

CSCuj59545

SSL connectivity to ASA stops working on failover

CSCuj68420

ASA SMR: Multicast traffic for some groups stops flowing after failover

CSCuj71626

ST not injected in mstsc.exe on 64-bit Win 8 IE 10 when started TSWebApp

CSCuj77219

ASA KCD traceback during domain leave or join

CSCuj83344

ASA traceback in Thread name - netfs_thread_init

CSCul00624

ASA: ARP Fails for Subinterface Allocated to Multiple Contexts on Gi0/6

CSCul02052

ASA fails to set forward address in OSPF route redistrubution

CSCul05200

Webvpn rewriter some links from steal.js are mangled incorrectly

CSCul07504

CWS: ASA forwards HTTPS packets to CWS tower in wrong sequence

CSCul08896

ASA Webvpn: Rewriter issue with dynamic iframes

CSCul10352

OpenSSH vulnerability CVE-2012-0814: Debug messages with key info

CSCul13258

ASA rejects certificates with NULL param in ECDSA/SHA signature alg

CSCul19727

NPE: Querying unsupported IKEv2 MIB causes traceback

CSCul26755

INSPECT ICMP ERROR  ICMP HEADER AFTER UN_NAT DOES NOT MATCH IP DST ADDR

CSCul28082

ASA traceback in Thread Name: DATAPATH due to double block free

CSCul33074

ASA: Hitless upgrade fails with port-channels

CSCul34143

ENH: Need to optimize messages printed on upgrade from 8.2- to 8.3+

CSCul37560

ASA traceback when uploading an image using FTP

CSCul37888

traffic does not match time-rang access-list configured with policy-maps

CSCul41183

ASA 5585 High Memory due to dACLs installed from cut-through-proxy

CSCul41447

ASA: Memory leak with WebVPN and HTTP server enabled simultaneously

CSCul47481

ASA WebVPN Login portal returns to login page after successful login

CSCul49796

ASA Tranparent A/A - Replicated MAC addresses not deleted after timeout

CSCul60058

Case sensitivity check missing for Web Type ACL and Access-group

CSCul60950

IPSEC VPN - One crypto ACE mismatch terminates all Phase2 with that peer

CSCul61939

Webvpn: ASA  fails to rewrite javascript tag correctly

CSCul62357

ASA fails to perform KCD SSO when web server listens on non-default port

CSCul64980

Acct-stop for VPN session doesn't send out when failover occurred

CSCul70712

ASA: ACL CLI not converting 0.0.0.0 0.0.0.0 to any4

CSCul73785

WEBVPN multiple issues with LMS application

CSCul74286

ASA: Phy setting change on member interfaces not seen on port-channel

CSCul77465

BPDUs on egress from ASA-SM dropped on backplane

CSCul83331

Redundant IFC not Switching Back

CSCul84216

ASA - Remote access VPN sessions are not replicated to Standby unit

CSCul90151

ASA EIGRP redistribute static shows up as internal route

CSCul95239

Copying configuration to running-config fails

CSCul96580

ASA tears down SIP signaling conn w/ reason Connection timeout

CSCul96864

ASA translates the source address of OSPF hello packets

CSCul98420

'Route-Lookup' Behavior Assumed for Twice NAT with Identity Destination

CSCum00556

Page fault traceback in DATAPATH under DoS, rip qos_topn_hosts_db_reset

CSCum00826

ASA reloads on Thread name: idfw_proc

CSCum01313

ASA drops DHCP Offer packet in ASP when nat configured with "Any"

CSCum16576

ASA not allowing AC IKEv2 Suite-B with default Premium Peer license

CSCum24634

IKEv1 - Send INVALID_ID_INFO when received P2 ID's not in crypto map

CSCum32334

WebVPN: ASA webVPN fails to rewrite dynamic content of pubmed website

CSCum35118

ASA:Traceback in Thread Name: DATAPATH-23-2334

CSCum37080

Traceback in IKEv2 Daemon with AnyConnect Failure

CSCum39328

uauth session considered inactive when inspect icmp is enabled

CSCum39333

idle time field is missing in show uauth output

CSCum47174

WebVPN configs not synchronized when configured in certain order-v3

CSCum54163

IKEv2 leaks embryonic SAs during child SA negotiation with PFS mismatch

CSCum60784

ASA traceback on NAT assert on file nat_conf.c

CSCum65278

ASA 5500-X: Chassis Serial Number missing in entity MIB

CSCum68923

Webvpn: connecting to oracle network SSO returns error

CSCum68951

Webvpn: web applications that may refresh a page with "#" fail

CSCum69144

HTTP redirect to the VPNLB address using HTTPS fails in 9.1.4/9.0.4.x

CSCum82760

ASA traceback in Unicorn Admin Handler

CSCum82840

ASA: Traceback in pix_flash_config_thread when upgrading with names

CSCum84247

ASA - VPN session leak for IKEv2 if L2L sessions land on RA tunnel group

CSCum85858

ASA Cluster: Unable to stop captures on CCL in a context

CSCum93731

ASA 9.1.3 SNMP Traceback in Thread Name: SNMP

CSCum94542

Traceback in Thread Name: ci/console

CSCum95843

IKEv2 routes not installed if Dynamic and Static Crypto Map Match

CSCun04658

Assigned IP in show vpn-sessiondb anyconnect is missing.

CSCun09515

capture option to be provided to collect pcap frm node other than master

CSCun10189

Ping doesn't work between peer IPs when answer-only is configured

CSCun11074

ASA:Tracebacks in thread dispatch unit due to SunRPC inspection

CSCun21186

ASA traceback when retrieving idfw topn user from slave

 

 

Revision:  Version 9.0.(4)1 – 1/22/2014

Files:  asa904-1-smp-k8.bin, asa904-1-k8.bin

Defects resolved since 9.0(4):

 

CSCuh44052

ASA sip inspection memory leak

CSCui44095

ASA 9.1: timer app id was corrupted and causing Dispatch Unit traceback

 

CSCui53710

ACL Migration to 8.3+ Software Unnecessarily Expands Object Groups

 

CSCui63001

ASA traceback in Thread Name: fover_parse during command replication

 

CSCuj33496

Privillage level 0 users getting full access

CSCuj50870

ASA in failover pair may panic in shrlock_unjoin

 

CSCuj54639

ASA drops inspected HTTP when unrelated service-policy is removed

 

CSCuj79509

ASA Physical Interface Failure Does not Trigger Failover

 

CSCuj82692

ASA 8.4.7 - Traceback with assertion in thread name Dispatch Unit

 

CSCuj94335

watchdog at ci_delayed_acl_elem_addition when object-group-search access

 

CSCul11741

Removing ports from service object-group does not remove from the ACL

 

CSCul17354

Traceback after upgrade from pre-8.3 to 8.3 and above

 

CSCul18059

Object Group Search may cause ACL to be matched incorrectly

 

CSCul25576

ASA: Page fault traceback after running show asp table socket

 

CSCul46582

ASA: Out of order Fin packet leaves connection half closed

 

CSCul52942

ASA failover cluster traceback when replicating the configuration

 

CSCul65069

ASA Assert Traceback in Dispatch Unit during LU Xlate replication

 

CSCul70099

ASA SSL VPN Privilege Escalation Vulnerability

CSCum06272

ASA reloads due to SSL processing