Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.3(3)11 – 10/19/2016

Files:  asa933-11-smp-k8.bin

Defects resolved since 9.3(3)10:

 

CSCuy54567

Evaluation of pix-asa for OpenSSL March 2016

CSCuz47295

Cisco ASA Software Local Certificate Authority Denial of Service Vulnerability

CSCuz52474

Evaluation of pix-asa for OpenSSL May 2016

CSCvb19843

Buffer Overflow in ASA Leads to Remote Code Execution

 

 

Revision:  Version 9.3(3)10 – 08/24/2016

Files:  asa933-10-smp-k8.bin

Defects resolved since 9.3(3)9:

 

CSCuz80281

IPv6 neighbor discovery packet processing behavior

CSCva92151

Cisco ASA SNMP Remote Code Execution Vulnerability

 

 

Revision:  Version 9.3(3)9 – 03/08/2016

Files:  asa933-9-smp-k8.bin

Defects resolved since 9.3(3)7:

 

CSCtx43501

CPU hog due to snmp polling of ASA memory pool information

CSCun21186

ASA traceback when retrieving idfw topn user from slave

CSCuo08193

Traceback in Thread Name: DATAPATH-1-1382 while processing nat-t packet

CSCuq97035

WEBVPN: Citrix 5/6 application doesn't launch with IE10/Windows 7

CSCur07369

SXP Version Mismatch Between ASA & N7K with clustering

CSCur09141

RRI static routing changes not updated in routing table

CSCur51051

LU allocate connection failed on the Standby ASA unit

CSCur87011

ASA low DMA memory on low end ASA-X -5512/5515 devices

CSCus08239

ASDM upload causes traceback, OCTEON_CRYPTO: SG buffers exceeds limit

CSCus10787

Transactional ACL commit will bypass security policy during compilation

CSCus16416

Share licenses are not activated on failover pair after power cycle

CSCus34033

ASA fails to pass ipv6 address to anyconnect client when using RADIUS

CSCus53126

ASA traffic not sent properly using 'traffic-forward sfr monitor-only'

CSCus92856

ASA traceback in DATAPATH Thread due to Double Block Free

CSCut01856

ASA dropping traffic with TCP syslog configured in multicontext mode

CSCut03981

ASA SSLVPN Client cert validation failure - SSL Lib error: Bad RSA Sig

CSCut10078

Standby ASA does not apply OSPF route after config replication

CSCut12513

ASA allows citrix  ICA connection without authentication

CSCut15570

Anyconnect SSL VPN certificate authentication fails o ASA

CSCut37974

EIGRP authentication not working with simple pasword

CSCut39985

Per-session PAT RST sent to incorrect direction after closing session

CSCut40770

Interface TLV to SFR is corrupt when frame is longer than 2048 bytes

CSCut49034

ASA: High CPU on standby due to RDP conn to AC client from CL SSL portal

CSCut49111

ASA traceback because of TD tcp-intercept feature

CSCut49724

Corrupted host name may occur with DHCP

CSCut54218

ASA tunnel-group"password-expire-in-days"not prompting a password change

CSCut67779

Investigate impact of jumbo-frame reservation on low-end ASA platforms

CSCut71095

ASA WebVPN clientless cookie authentication bypass

CSCut95793

ASA: Anyconnect IPv6 Traceroute does not work as expected

CSCuu04012

ASA CX - Data Plane marked as DOWN untill ASA reload.

CSCuu18527

ASA WebVPN: HTTP 302 Location URL rewritten incorrectly

CSCuu18989

ASA %ASA-3-201011: Connection limit exceeded when not hitting max limit

CSCuu27334

ASA: Traceback with Thread Name - AAA

CSCuu28909

ASA cluster: ICMP loop on CCL for ICMP packet destined to the VPN tunnel

CSCuu31751

ASA OSPF database not reflect changes

CSCuu32905

ASA WebVPN: Javascript fails to execute when accessing internal portal

CSCuu45812

asa Traceback with Thread Name idfw_proc

CSCuu45813

ASA Name Constraints dirName improperly verified

CSCuu46569

ASA CA certificate import fails with different types of Name Constraints

CSCuu48197

ASA: Stuck uauth entry rejects AnyConnect user connections

CSCuu52976

ASA not checking the MAC of the TLS records

CSCuu56912

ASA change non-default port to 443 for https traffic redirected to CWS

CSCuu61573

9.5.2 Gold Setup - Traceback in DATAPATH-6-2596 snp_fp_get_frag_chain

CSCuu73395

Auth-prompt configured in one context appears in another context

CSCuu73716

Traceback in Thread CP Processing

CSCuu75901

ASA failover due to issue show local-host command make CPU-hog

CSCuu78835

Webvpn rewrite issues for Confluence - by atlassian on latest v6.4.5

CSCuu84085

DHCP-DHCP Proxy thread traceback shortly after failover and reload

CSCuu84697

ASA Traceback in  Thread Name ssh/client

CSCuu86195

conn-max counter is not decreased accordingly

CSCuu88412

When > 510 characters entered in CLI, context switches to admin/system

CSCuu91304

Immediate FIN from client after GET breaks scansafe connection

CSCuu94945

ASA: Traceback while copying file using SCP on ASA

CSCuv01177

ASA: traceback in IDFW AD agent

CSCuv05386

Clientless webvpn on ASA does not display asmx files

CSCuv07106

ASATraceback in ssh whilst adding new line to extended ACL

CSCuv09538

ASA: CLI commands not showing help(?) options for local authorization

CSCuv10258

ASA5505 permanent base license, temp secplus, failover, vlan count issue

CSCuv10938

'redistribute' cmds under 'router eigrp' removed on deleting any context

CSCuv12884

Unable to authenticate with remove aaa-server from different context

CSCuv20449

Traceback in Thread Name: ssh when using capture or continuous ping

CSCuv38654

rewriter returns 302 for a file download

CSCuv39775

ASA cluster-Incorrect "current conns" counter in service-policy

CSCuv43902

ASA: Watchdog Traceback with Thread Name:- SXP CORE

CSCuv45756

ASA may tracebeck when displaying packet capture with trace option

CSCuv49446

ASA traceback on Standby device during config sync in thread DATAPATH

CSCuv50709

Standby ASA inside IP not reachable after Anyconnect disconnect

CSCuv51649

SSL : Unable to Join nodes in Cluster

CSCuv57389

ASA PKI: cert auth fails after upgrade to 9.1(6.4) / 9.1(6.6) / 9.1(6.8)

CSCuv58559

Traceback in Thread Name: DATAPATH on modifying "set connection" in MPF

CSCuv66333

ASA picks incorrect trustpoint to verify OCSP Response

CSCuv70932

FO: ASAv traceback while syncing during upgrade from 9.4.1 to 9.5.1

CSCuv79552

Standby traceback during config replication with customization export

CSCuv92371

ASA traceback: SSH Thread: many users logged in and dACLs being modified

CSCuv92384

ASA TCP Normalizer sends PUSH ACK for invalid ACK for half-open CONNS

CSCuv94338

ASA traceback  in Thread  Name: CP Crypto Result Processing.

CSCuw00971

ASA truncates url-redirect at 160 chars for ra vpn clients (ISE 1.3+)

CSCuw02009

ASA - SSH sessions stuck in CLOSE_WAIT causing ASA to send RST

CSCuw14334

Trace back with Thread Name: IP Address Assign

CSCuw16607

ASA EIGRP does not send poison reverse for neighbors to remove route

CSCuw17930

Improper S2S IPSec Datapath Selection for Remote Overlapping Networks

CSCuw19671

ASA traceback while restoring backup configuration from ASDM

CSCuw22130

ASA traceback when removing dynamic PAT statement from cluster

CSCuw24664

ASA:Traceback in Thread Name:- netfs_thread_init

CSCuw26991

ASA: Traceback in Thread Unicorn Admin Handler due to Threat Detection

CSCuw28735

Cisco ASA Software Version Information Disclosure Vulnerability

CSCuw36853

ASA: ICMP error loop on cluster CCL with Interface PAT

CSCuw39685

filter sfr traffic may cause  memory corruption

CSCuw41548

DNS Traceback in channel_put()

CSCuw44744

Traceback in WebVPN rewriter

CSCuw51576

SSH connections are not timed out on Standby ASA (stuck in rtcli)

CSCuw55813

Standby ASA traceback in Thread Name: EIGRP-IPv4

CSCuw66397

DHCP Server Process stuck if dhcpd auto_config already enabled from CLI

CSCuw85261

SAML won't be able select Oracle OAM tunnel group

CSCuw87331

ASA: Traceback in Thread name DATAPATH-7-1918

CSCuw87910

PCP 10.6 Clientless VPN Access is Denied when accessing Pages

CSCuw92005

Thread Name: DATAPATH-17-3095: ASA in Cluster Reloads Unexpectedly

CSCux03626

Traceback in thread name: Unicorn Proxy Thread

CSCux07002

ASA: assertion "pp->pd == pd" failed: file "main.c", line 192

CSCux09181

http-form authentication fails after 9.3.2

CSCux09310

ASA traceback when using an ECDSA certificate

CSCux20178

OSPF neighbor goes down after "reload in xx" commnad in 9.2 and later

CSCux23659

ASA 9.1.6.10 traceback after remove compact flash and execute dir cmd

CSCux26443

DAP URL-List Command Says It Supports 491 Characters; Only Supports 245

CSCux35272

ASA TCP normalizer checksum verification cannot be disabled

CSCux37303

Port-Channel Config on Gi 0/0 causes Boot Loop - FIPS related

CSCux37442

Cisco signed certificate expired for WebVpn Port Forward Binary on ASA

CSCux41145

Evaluation of pix-asa for OpenSSL December 2015 Vulnerabilities

CSCux45179

SSL sessions stop processing -"Unable to create session directory" error

CSCux59122

ASA L7 policy-map comes into affect only if the inspection is re-applied

CSCux69987

ASA: Traceback on ASA device after adding FQDN objects in NAT rule

CSCux72610

ASA TACACS+: process tacplus_snd uses large percentage of CPU

CSCux81683

ASA Traceback on Thread Name: Unicorn Admin Handler

CSCux85725

ASA WebVPN: Java RDP Plugin does not launch

CSCux87457

ASA traceback in Thread  Name: https_proxy

CSCux88237

ASA traceback in DATAPATH thread

CSCuy01420

ASA traceback in Thread Name: Unicorn Proxy Thread.

CSCuy03024

ASA traceback and reload citing Thread Name: idfw_proc

CSCuy11905

ASA 5585 traceback when the User name is mentioned in the Access list

CSCuy13937

ASA Watchdog traceback in CP Processing thread during TLS processing

 

 

Revision:  Version 9.3(3)7 – 01/14/2016

Files:  asa933-7-smp-k8.bin

Defects resolved since 9.3(3)6:

 

CSCux29978

ASA IKEv1 and IKEv2 Vulnerability

 

CSCux42019

IKEv2 Fragments may get dropped with a specific sequence of fragments

 

 

Revision:  Version 9.3(3)6 – 10/30/2015

Files:  asa933-6-smp-k8.bin

Defects resolved since 9.3(3)2:

 

CSCus27650

Cut Through proxy not working correctly with TLS1.2

 

CSCus37840

AnyConnect upgrade from AC 2.5 to AC 3.1 fails

 

CSCus46895

WebVPN Rewriter: "parse" method returns curly brace instead of semicolon

 

CSCus57142

ASA traceback in threadname Checkheaps when it hits dhcpv6 packet

 

CSCus62863

Kenton 5516: Interface dropping ARPs after flapping under traffic load

 

CSCus63269

HTTP redirect to the VPNLB address using HTTPS fails in 9.1.5

 

CSCus94026

ISAKMP SERVER traffic from codenomicon crashes ASA

CSCut64327

L2TP/IPsec traffic dropped due to "vpn-overlap-conflict"

 

CSCut67965

CRYPTO_PKI: ERROR: Unable to allocate new session. Max sessions reached

 

CSCut86523

ASA: Silently Drops packets with SFR Module installed.

 

CSCut88287

ASA Traceback in vpnfol_thread_msg

 

CSCut92194

ASA traceback in Thread Name: CP Processing

 

CSCuu00733

ASA: ECMP stopped working after upgrade to 9.3.2

 

CSCuu25430

Object nat rule is not matched

 

CSCuu36639

ASA 5506X: ESP Packet drop due to crypto accelerator ring timeout

 

CSCuu39615

eglibc 2.18 is missing upstream fix #15073

 

CSCuu39636

Cert Auth fails with 'max simultaneous-login restriction' error

 

CSCuu48626

ASA - access list address argument changed from host 0.0.0.0 to host ::

 

CSCuu53928

ASA does not set forward address or p-bit in OSPF redistrubution in NSSA

 

CSCuu63656

ASA not generating PIM register packet for directly connected sources

 

CSCuu83280

Evaluation of OpenSSL June 2015

 

CSCuu87823

ASAv traceback in DATAPATH when used for WebVPN

 

CSCuu99349

ASA-3-317012 and "No route to host" errors even though the route exists

 

CSCuv01022

ASA:OSPF over L2L tunnels is not working with multiple cry map entries

 

CSCuv05916

Need to prevent crash in js_parser_print_rest

 

CSCuv11566

ASA LDAP CRL query baseObject DN string is malformed

 

CSCuv12564

Memory leak @regcomp_unicorn with APCF configured

 

CSCuv30184

AddThis widget is not shown causing Traceback in Unicorn Proxy Thread

 

CSCuv32615

ASA: LDAP over SSL Authentication failure

 

CSCuv42413

Dynamic Route Not Installed After Failover

 

CSCuv69235

HTTP chunked data causing watchdog

 

CSCuv86500

Webvpn: JS parser may crash if the underlying connection is closed

 

CSCuv87150

ASA traceback in Thread Name: fover_parse (ak47/ramfs)

 

CSCuv87760

Unicorn proxy thread traceback with RAMFS processing

 

CSCuv91730

Request allow packets to pass when snort is down for ASA configurations

 

CSCuv96011

OSPF over IKEv2 L2L tunnel is broken on ASA with 9.2.1 onwards

 

CSCuw09578

ASA 9.3.3.224 traceback in ak47_platform.c  with WebVPN  stress test

 

 

 

Revision:  Version 9.3(3)2 – 06/11/2015

Files:  asa933-2-smp-k8.bin

Defects resolved since 9.3(3)1:

 

CSCuu66218

ASA is not correctly handling errors on AES-GCM ICV

 

 

Revision:  Version 9.3(3)1 – 05/22/2015

Files:  asa933-1-smp-k8.bin

Defects resolved since 9.3(3):

 

CSCuq57307

ASA 8.4 Memory leak due to duplicate entries in ASP table

CSCuq99821

ASA/ASASM drops SIP invite packets with From field containing "" and \

CSCur07061

Traceback on standby ASA during hitless upgrade

CSCur20322

ASA 9.2.1 - DATAPATH Traceback  in L2 cluster environment

CSCus32005

ASA - Traceback in thread name SSH while applying BGP show commands

CSCus47259

Cisco ASA XAUTH Bypass Vulnerability

CSCus70693

ASA 9.3.2 SSL doesn't work with error: %ASA-4-402123: CRYPTO:

CSCus78450

Certificate Validation Failure after upgrade post 9.1.5(12)

CSCus91407

Network Object NAT is not working when config-register == 0x41

CSCus97061

ASA Cluster member traceback in DATAPATH

CSCut27332

ASA traceback in aaa_shim_thread

CSCut28217

Active ASA  in failover setup reboots on its own

CSCut30741

ASA redirection to Scansafe tower fails with log id "775002" in syslog

CSCut44082

EIGRP configuration not being correctly replicated between failover ASAs

CSCut46019

MARCH 2015 OpenSSL Vulnerabilities

CSCut48009

Traceback in thread CP Processing

CSCut58935

WebVPN: Tsweb fails to work through clientless portal