Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  Each individual fix in the release was unit tested and verified, and the image Ser0tta3

had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.2(4)33 – 05/04/2018

Files:  asa924-33-smp-k8.bin

Defects resolved since 9.2(4)28:

 

CSCvf85065

ASA: Traceback by Thread Name idfw_proc

CSCvg56122

SSL handshake fails with large certificate chain size

CSCvh85514

ASA Traceback in Thread Name: Unicorn Proxy Thread

CSCvh91399

upgrade of ASA5500 series firewalls results in boot loop (not able to get past ROMMON)

CSCvh95325

Standby ASA traceback during replication from mate 9.2(4)27

CSCvi58089

Memory leak on webvpn

CSCvc19931

Crashes on back-to-back 'clear config all' when IKEv1 SA established

 

 

Revision:  Version 9.2(4)28 – 03/20/2018

Files:  asa924-28-smp-k8.bin

Defects resolved since 9.2(4)27:

 

CSCva92997

9.7.1 traceback in snp_fp_qos

CSCvh90947

ASA traceback with Thread Name: fover_parse

 

 

Revision:  Version 9.2(4)27 – 02/03/2018

Files:  asa924-27-smp-k8.bin

Defects resolved since 9.2(4)26:

 

CSCvf63718

Cisco Adaptive Security Appliance Flow Creation Denial of Service Vulnerability

CSCvh79732

Cisco Adaptive Security Appliance Denial of Service Vulnerability

CSCvh81870

Memory leak in IKE for aggregate-auth

 

 

Revision:  Version 9.2(4)26 – 01/05/2018

Files:  asa924-26-smp-k8.bin

Defects resolved since 9.2(4)25:

 

CSCto19051

Resolve any vulnerabilities in ASA/Firepower Threat Defense Heimdal code

CSCvb53233

ASA 9.1(7)9 Traceback with %ASA-1-199010 and %ASA-1-716528 syslog messages

CSCvd00293

VTI - Some sessions do not get cleared from vpn-sessiondb

CSCvd53381

ASA Traceback when saving/viewing the configuration due to time-range ACLs

CSCve20395

ASA Portal Java plug-ins fail with the latest Java updates

CSCve73025

All 1700 "4 byte blocks" were depleted after a weekend VPN load test.

CSCve77049

ASA Memory depletion due to scansafe inspection

CSCvf03676

Ports not getting reserved on ASA after adding snmp configuration.

CSCvf28749

ASA not sending register stop when mroute is configured

CSCvf61419

Traceback in thread DATAPATH due to NAT

CSCvf63108

ASA drops the IGMP Report packet which has Source IP address 0.0.0.0

CSCvf79262

OpenSSL CVE-2017-3735 "incorrect text display of the certificate"

CSCvf89504

ASA cluster intermittently drop IP fragments when NAT is involved

CSCvg01132

ASA : After upgrading from 9.2(4) to 9.2(4)18 serial connection hangs

CSCvg17478

Traceback with Show OSPF Database Commands

CSCvg25175

ASA getting stuck in hung state because of STATIC NAT configuration for SNMP ports

CSCvg51984

High CPU in IKE Daemon causing slow convergence of VPN tunnels in a scaled environment

CSCvg53981

dir /recursive cache:/stc and "dir cache:stc/2/" list AnyConnect.xsd differently on ASA9.8.2

CSCvg57954

Modifying service object-groups (add and remove objects) removes ACE

CSCvg58385

ASA reports incorrectly double input packets traffic on PPPoe/VPDN interface

CSCvg81583

Split brain after recovery from interface failure when fover and then data ifc goes down in order.

CSCvg90820

SSPs with ASA in multiple context moves in active-active situation while failover is occurring

CSCvh32323

Memory leak in idfw component on ASA

CSCtw80509

add "show resource usage summary count all 1" to show tech

CSCuw37752

FTP data conn scaling fails with dynamic PAT

CSCuj98977

ASA Traceback in thread SSH when ran "show service set conn detail"

 

 

Revision:  Version 9.2(4)25 – 01/05/2018

Files:  asa924-25-smp-k8.bin

Defects resolved since 9.2(4)24:

 

CSCvg97652

Legacy Cisco ASA 5500 may be vulnerable to a Bleichenbacher attack on TLS

CSCvg35618

Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability

 

 

Revision:  Version 9.2(4)24 – 09/14/2017

Files:  asa924-24-smp-k8.bin

Defects resolved since 9.2(4)22:

 

CSCuv88898

WEBVPN Rewriter: Stops mangling after hex code of Period on Bookmark URL

CSCuv63875

ASA traceback in Thread Name:ci/console while running show ospf commands

CSCuz72137

ASA dropping packets with "novalid adjacency" though valid ARP entry avail

CSCvc07112

Implement detection and auto-fix capability for scheduler corruption problems

CSCvc18200

print the thread name for non-crashing threads in crash info

CSCvc82270

ASA 1550 block gradual depletion

CSCvd01130

ASA TCP SIP inspection translation not working when IP phone is behind VPN tunnel

CSCvd50107

ASA traceback in Thread name: idfw_proc on running "show access-list", while displaying remark

CSCvd59063

Cisco Adaptive Security Appliance Authentication Denial of Service Vulnerability

 

CSCvd71473

ASA: slow memory leak when using many DNS queries

CSCvd79797

ASA local dns resolution fails when dns server is reachable through a site to site ipsec tunnel

CSCve02469

ASA Issue with bgp route summarization(auto-summary)and route advertisement

CSCve04326

Slave should have use CCL to forward traffic instead of blackholing when egress interface is down

CSCve14758

Standby ASA not learning routes via RIP

CSCve23784

ASA may traceback on displaying access-list config or saving running config

CSCve42583

ASA: IPv6 protocol X rule for passing through FW is dropping packets with Invalid IP length message

CSCve47393

OSPF Rogue LSA with maximum sequence number vulnerability

CSCve57150

vpn vlan mapping issue

CSCve60829

ASA Cluster : Potential UDP loop on cluster link with PAT pool

CSCve63762

ASASM: Interface vlans going to admin down after reload.

CSCve78986

ASA/ 9.6.3 // WebVPN Smart tunnel works but floods windows with event viewer

CSCvf01873

Regex is not matching for HTTP argument field

CSCvf16142

ASA-5-720012:(VPN-Secondary)Failed to update IPSec failover runtime data in ASA cluster environment

CSCvf16429

Ikev2 Remote Access client sessions stuck in Delete state

CSCvf41547

traceback in watchdog process

CSCvf54981

ASA - 80 Byte memory block depletion

 

 

Revision:  Version 9.2(4)22 – 05/30/2017

Files:  asa924-22-smp-k8.bin

Defects resolved since 9.2(4)20:

 

CSCut07712

ASA - TO the box traffic break due to int. missing in asp table routing

CSCut09459

incorrect failover status for contexts via SNMP

CSCuv11963

TP Auth fails when sub CA using RSA keys is signed by root using ECDSA

CSCuv61791

CWS redirection on ASA may corrupt sequence numbers with https traffic

CSCux70993

ASA unable to add policy NAT which is overlapping with ip local pool

CSCuy06125

Re-adding context creates context without configs on some slaves

CSCuy43438

L2TP over IPSec can not be connected after disconnection from client.

CSCuy55468

Unicorn Proxy Thread causing CP contention

CSCuy80830

ASA failed to allow tcp traffic from inside to outside

CSCuz89989

Ikev1 tunnel drops with reason  Peer Address Changed

CSCva22048

ASA: SIP Call Drops with PAT when same media port used in multiple calls

CSCva31378

ASA treaceback at Thread Name: rtcli async executor process

CSCva38556

Cisco ASA Input Validation File Injection Vulnerability

CSCva92975

ASA 5585-60 dropping out of cluster with traceback

CSCva98240

SIP: Address from Route: header not translated correctly

CSCvb19492

ASA stops processing DHCP Offers in a based RAVPN

CSCvb29688

Stale VPN Context entries cause ASA to stop encrypting traffic despite fix for CSCup37416

CSCvb38522

ASA PKI OCSP failing - CRYPTO_PKI: failed to decode OCSP response data.

CSCvb50301

ASA traceback at Thread Name: rtcli

CSCvb58087

Object-group-search redundant service group objects are incorrectly removed

CSCvb74249

ASA dropping traffic with TCP syslog configured in multicontext mode

CSCvb75685

EZVPN NEM client can't reconnect after no vpnclient enable is entered

CSCvb92125

ASA drops DNS PTR Reply with reason Label length exceeded during rewrite

CSCvb92548

ASA matches incorrect ACL with object-group-search enabled

CSCvb92823

ASA SIP inspection may delay transmission of 200 OK when embedded with NOTIFY

CSCvc05005

ASA cluster TCP/SSL ports are not displayed on LISTEN state

CSCvc06150

ASA unable to add multiple attribute entries in a certificate map

CSCvc14502

ASA multicontext disallowing new conns with TCP syslog unreachable and logging permit-hostdown set

CSCvc19318

ASA traceback at Thread Name: sch_syslog

CSCvc23838

Cisco ASA Heap Overflow in Webvpn CIFS

CSCvc24380

Traceback on thread name IKE Daemon at mqc_enable_qos_for_tunnel

CSCvc24657

MIB object cempMemPoolHCUsed disappeared

CSCvc25409

ASA memory leak in CloneOctetString when using SNMP polling

CSCvc36535

ASA traceback in Thread Name: ssh, rip igb_disable_rx_queues after no shutdown of interface

CSCvc38425

ASA with FirePOWER module generates traceback and reloads or causes process not running

CSCvc52072

Webvpn portal not displayed corrrectly for connections landing on default webvpn group.

CSCvc55974

ikev2 handles get leaked in a L2L setup

CSCvc58272

ASA incorrectly processing negative numbers in wrappers, resulting in graphical webvpn issue

CSCvc60254

SIP: 200 OK messages with multiple seqments not reassembled correctly

CSCvc61818

CTP after failed attempt sends the domain along with the username

CSCvc62556

Traceback in ASA Cluster Thread Name: qos_metric_daemon

CSCvc79371

ASA nat pool not getting updated correctly.

CSCvc83462

gzip compression not working via Webvpn

CSCvc87914

ASA traceback and Reload on Config Sync Failure

CSCvc88411

1550-byte block depletion seen due to Radius Accounting packets

CSCvc93947

ASA(9.1.7.12):Connection entries created for multicast streams through standby ASA.

CSCvd01736

L2TP connects only sometimes when DHCP used

CSCvd10251

Insufficient TCP options validation at 2nd normalizer in tcp_norm_parse_ts

CSCvd21541

Cannot delete port-object once created under the Service object group in ASA 944

CSCvd23471

ASA may traceback while loading a large context config during bootup

CSCvd24066

ASA drops web traffic when IM inspection is enabled.

CSCvd39113

Cluster C-Hash table is updated with one more unit despite the new unit didn't join the setup

CSCvd50389

RT#687120: Bookmark Issue with clientless VPN - SAML

CSCvd53884

ASA FirePOWER module data plane down after reload of module

CSCvd58417

DCERPC inspection drops packets and breaks communication

CSCvd62509

ASA traceback in Thread Name: accept/http when ASDM is displaying Access Rules

CSCvd64416

ASA All contexts use the same EIGRP router-ID upon a reload

CSCvd65797

ASA May crash when changing a NAT related object to fqdn

CSCvd68518

Traceback in Thread Name: Unicorn Admin Handler

CSCvd77893

ASA may generate an assert traceback while modifying access-group

CSCvd99859

ASA may drop DNS reply containing only additional RR of type TXT

CSCve05841

ASA reloaded while joining cluster and active as slave

CSCve08947

In multi-context ASA drops traffic sourced from certain ports when interface PAT is used

CSCve16198

ASA 5585 failover secondary traceback on Thread name: idfw_proc

CSCve23091

Auto-RP packet is dropped due to no-route - No route to host

CSCve91068

Cisco Adaptive Security Appliance HREF Cross Site Scripting Vulnerability

 

Revision:  Version 9.2(4)20 – 04/03/2017

Files:  asa924-20-smp-k8.bin

Defects resolved since 9.2(4)18:

 

CSCvb48640

Evaluation of pix-asa for Openssl September 2016

 

CSCvd59063

Cisco Adaptive Security Appliance Authentication Denial of Service Vulnerability

CSCvd78303

ARP functions fail after 213 days of uptime, drop with error 'punt-rate-limit-exceeded'

 

 

 

Revision:  Version 9.2(4)18 – 11/18/2016

Files:  asa924-18-smp-k8.bin

Defects resolved since 9.2(4)17:

 

CSCuq80704

ASA classifies TCP packets as PAWS failure incorrectly

CSCuw95262

After some time flash operations fail and configuration can not be saved

CSCux92157

ASA Traceback Assert in Thread Name: ssh_init with component ssh

CSCuy47545

http config missing in multicontext after reload of stdby 916.9 or later

CSCuy89288

AnyConnect DTLS on-demand DPDs are not sent intermittently

CSCva00190

ASA 9.4.2.6 High CPU due to CTM message handler due to chip resets

CSCva41711

WebVPN caches incomplete downloads

CSCva69799

ASA stuck in boot loop due to FIPS Self-Test failure

CSCva77852

ipsecvpn-ikev2_oth: 5525 9.4.2.11 traceback in Thread Name: IKEv2 Daemon

CSCva85382

ASA memory leak for CTS SGT mappings

CSCva90419

issuer-name falsely detecting duplicates in certificate map using attr

CSCva90806

ASA Traceback when issue 'show asp table classify domain permit'

CSCva94702

Enqueue failures on DP-CP queue may stall inspected TCP connection

CSCvb03994

Traceback in IKE_DBG

CSCvb05667

H.323 inspection causes Traceback in Thread Name: CP Processing

CSCvb14664

ASA traceback in ipsecvpn-crypto

CSCvb14997

ASA DHCP Relay rewrites netmask and gw received as part of DHCP Offer

CSCvb19251

ASA as DHCP relay drops DHCP 150 Inform message

CSCvb21922

Remove ACL warning messages in show access-list when FQDN is unresolved

CSCvb22435

ASA Traceback in thread name CP Processing due to DCERPC inspection

CSCvb31833

Traceback : ASA with Threadname: DATAPATH-0-1790

CSCvb32297

WebVPN:VNC plugin:Java:Connection reset by peer: socket write error

CSCvb36199

Thread Name: snmp ASA5585-SSP-2 running 9.6.2 traceback

CSCvb39147

Lower NFS throughput rate on Cisco ASA platform

CSCvb49445

IKEv2: It is NOT cleaning the sessions after disconnected from the client.

CSCvb63503

AAA session handle leak with IKEv2 when denied due to time range

CSCvb64161

ASA fairly infrequently rewrites the dest MAC address of multicast packet for client

 

 

Revision:  Version 9.2(4)17 – 10/12/2016

Files:  asa924-17-smp-k8.bin

Defects resolved since 9.2(4)14:

 

CSCub34054

L2 Clustering:OSPFv2, Eigrp and OSPFv3 RIB not replicated to slave node

CSCuh99564

Password change page can be displayed without authentication

CSCum74032

ASA traceback on standby when SNMP polling

CSCup37416

Stale VPN Context entries cause ASA to stop encrypting traffic

CSCuu50708

ASA Traceback on 9.1.5.19

CSCuw40468

DHCP proxy overrites chosen DHCP server in multiple DHCP server scenario

CSCux17527

ASA memory leak related to Botnet

CSCux98029

ASA reloads with traceback in thread name DATAPATH or CP Processing

CSCuy00296

Traceback in Thread: IPsec message handler

CSCuy25163

Cisco ASA ACL ICMP Echo Request Code Filtering Vulnerability

CSCuz00077

ASA 9.1.6.4 traceback with Thread Name: telnet/ci

CSCuz06499

WebVPN: Webpage not fully rewritten when ASA has the same FQDN as srv

CSCuz09255

ASA does not respond to NS in Active/Active HA

CSCuz14808

5585-10 traceback in Thread Name: idfw_proc

CSCuz16398

Incorrect modification of NAT divert table.

CSCuz38888

WebVPN rewrite fails for MSCA Cert enrollment page / VBScript

CSCuz40081

ASA memory leak due to vpnfo

CSCuz42390

ASA Stateful failover for DRP works intermittently

CSCuz44968

Commands not installed on Standby due to parser switch

CSCuz63531

Observing Memory corruption, assert for debug ospf

CSCuz66661

ASA Cut-through Proxy inactivity timeout not working

CSCuz70330

ASA: SSH being denied on the ASA device as the maximum limit is reached

CSCuz79800

ASA cant delete ACL lines and remarks - Specified remark does not exist

CSCuz92074

ASA with PAT fails to untranslate SIP Via field that doesnt contain port

CSCuz94862

IKEv2: Data rekey collisions can cause inactive IPsec SAs to get stuck

CSCuz98220

ASA traceback with Thread Name: Dispatch Unit

CSCva00939

Remove ACL warning messages in show access-list when FQDN is resolved

CSCva01570

Unexpected end of file logon.html in WebVPN

CSCva02817

ASA not rate limiting with DSCP bit set from the Server

CSCva03607

show service-policy output reporting incorrect values

CSCva16471

IPv6 OSPF routes do not update when a lower metric route is advertised

CSCva35439

ASA DATAPATH traceback (Cluster)

CSCva36884

Cisco ASA Cross Site Scripting SSLVPN Vulnerability

CSCva68987

ASA drops ICMP request packets when ICMP inspection is disabled

CSCva69584

OSPF generates Type-5 LSA with incorrect mask, which gets stuck in LSDB

CSCva71484

ASA Memory leak due to VPN connection

CSCva84635

ASA: CHILD_SA collision brings down IKEv2 SA

CSCva87160

OTP authentication is not working for clientless ssl vpn

 

 

Revision:  Version 9.2(4)14 – 08/24/2016

Files:  asa924-14-smp-k8.bin

Defects resolved since 9.2(4)13:

 

CSCuz80281

IPv6 neighbor discovery packet processing behavior

CSCva92151

Cisco ASA SNMP Remote Code Execution Vulnerability

 

 

Revision:  Version 9.2(4)13 – 06/27/2016

Files:  asa924-13-smp-k8.bin

Defects resolved since 9.2(4)10:

 

CSCtq90780

ASA allows removing address pool conf even if it is in use in grp-policy

CSCtw90511

Packet captures cause CPU spike on Multi-Core platforms due to spin_lock

CSCub30181

ASA doesn't set ACE inactive when time-range expires

CSCuo65775

Cisco ASA Information Disclosure Vulnerability

CSCup89922

ASA DNS lookups always prefer IPv6 response

CSCup93708

Error when same-security-traffic is deleted and added

CSCuq21426

Inspect-DNS: PTR Query failed when DNS-Doctoring enabled

CSCuq39567

Traceback in Thread Name qos_metric_daemon caused by asdm history enable

CSCuq49455

ASA not sending RST packet for connections dropped by Botnet filter

CSCuq65201

ASA Local CA generates unexpected renewal reminder message

CSCuq71796

Webvpn Logon Form Title alignment issue w/ strings {>20 character}

CSCuq78238

Inspect rule defaults in standby transparent context on write standby

CSCuq87632

User membership not updated in parent group

CSCuq95704

There are two certificates related to one trustpoint on standby unit.

CSCur02239

ASA ACL hitcount not correct for ACLs with service object groups

CSCur76771

scansafe feature is missing from registered module features

CSCus78722

inspect esmtp replace the packet data to 'X'

CSCut24490

L2TP/IPSec Optimal MSS is not what it's supposed to be

CSCut49724

Corrupted host name may occur with DHCP

CSCut67315

ASA :Top 10 Users status is not getting enabled from ASDM.

CSCut75983

ASA Traceback in PPP

CSCuu02635

Remove demo and eval warning for sfr monitor-only

CSCuu13345

Drop reasons missing from asp-drop capture

CSCuu16983

ASA: failover logging messages appear in user context

CSCuu19489

ASA inspection-MPF ACL changes not inserted into ASP table properly

CSCuu41142

IPv6 local host route fail when setting link-local/Global simultaneously

CSCuu54660

ASA Remote Access - Phase 1 terminated after xauth

CSCuu84085

DHCP-DHCP Proxy thread traceback shortly after failover and reload

CSCuu92632

ASA sets non-zero FA in OSPF for anyconnect redistrubuted network

CSCuv02619

Standby ipv6 address setting is not replicated to standby

CSCuw32125

ASA stacktrace in vpn client disconnect that had dACL applied

CSCux41876

ASA IPSEC crypto map set df-bit copy-df/clear-df does not take effect

CSCux55923

WebVPN: Unable to play certain online videos

CSCux58172

DAP: debug dap trace not fully shown after +1600 lines

CSCux66866

Traffic drop due to constant amount of arp on ASASM

CSCux70784

ASA traceback while viewing large ACL

CSCux70812

Add Asynchronous support for DHCP proxy

CSCux83705

DNS Reply Modification for Dual-Stack does not work as expected

CSCuy43857

ASA WebVPN: Java Exception with Kronos application

CSCuy54567

Evaluation of pix-asa for OpenSSL March 2016

CSCuy63642

ASA 9.1(6) traceback in webvpn-datapath : thread name "DATAPATH-2-1524"

CSCuy67333

SIP call transfer fail due to differences b/w fixing CallId and Refer-To

CSCuy74593

ASA AnyConnect IKEv2 scripts help customisations not served after reload

CSCuy87597

ASA - Traceback in CP Processing Thread During Private Key Decryption

CSCuy89425

AAA: RSA/SDI unable to set new PIN

CSCuy98769

Slow ASA OSPF interface transition from DOWN to WAITING after failover

CSCuy99280

ENH: ASAv should have a different pre-loaded cert

CSCuz06125

Active and Standby ASA use same MAC addr with only active MAC configured

CSCuz08625

ASA traceback in SSH thread

CSCuz09394

infinite loop in JS rewriter state machine when return followed by var

CSCuz18707

Intranet page does not load via WebVPN with JavaScript errors

CSCuz30425

Network command disappears from BGP after reload with name

CSCuz36938

Traceback on editing a network object on exceeding the max snmp hosts

CSCuz38115

ASA Tback when large ACL applied to interface with object-group-search

CSCuz38180

ASA: Page Fault traceback in DATAPATH on standby ASA after booting up

CSCuz38703

ASA capture type isakmp saving malformed ISAKMP packets

CSCuz41033

dynamic crypto map fails if named the same as static crypto map

CSCuz52474

Evaluation of pix-asa for OpenSSL May 2016

CSCuz53186

ASA AnyConnect CSTP Copyright message changed improperly

CSCuz54357

ASA Clientless SSLVPN HTTP URL Self Sanitizer Function Issues

CSCuz58142

ASA Access-list missing and losing elements Warning Message enhancement

CSCuz67349

ASA Cluster fragments reassembled before transmission with no inspection

CSCuz67596

ASA may Traceback with Thread Name: Unicorn Admin Handler

 

 

Revision:  Version 9.2(4)10 – 04/20/2016

Files:  asa924-10-smp-k8.bin

Defects resolved since 9.2(4)8:

 

CSCum70304

FIPS self test power on fails - fipsPostDrbgKat

CSCun17627

OSPFv2 neighborship flaps from Exstart to Down

CSCuq10239

Windows 8 with new JRE, IE is not gaining access to smart tunnel

CSCut10103

ASA 5545x Upgrade to 9.2(2)4 causes Traceback in Thread Name SSL

CSCut71095

ASA WebVPN clientless cookie authentication bypass

CSCuw44038

Watchdog traceback in ldap_client_thread with large number of ldap grps

CSCuw51576

SSH connections are not timed out on Standby ASA (stuck in rtcli)

CSCuw59382

Rewriter errors when access IEEE website search feature through portal

CSCux08783

CWS: ASA does not append XSS headers

CSCux08838

ASA: Traceback in Checkheaps

CSCux11440

ASA traceback in Unicorn Proxy Thread

CSCux29842

Primary and Secondary ASA in HA is traceback in Thread Name:DataPath

CSCux29929

ASA 9.4.2 traceback in DATAPATH

CSCux35272

ASA TCP normalizer checksum verification cannot be disabled

CSCux41622

"set connection timeout idle" is not applied.

CSCux70998

Reload in Thread Name: IKE Daemon

CSCux71197

"show resource usage" gives wrong number of routes after shut/no sh

CSCux82835

Nat pool exhausted observed when enabling asp transactional-commit nat

CSCux94598

ASA using a huge dynamic ACL may cause Anyconnect connectivity failures

CSCuy05949

ASA: MAC address changes on active context when WRITE STANDBY is issued

CSCuy07753

Smart tunnel does not work since Firefox 32bit  version 43

CSCuy11905

ASA 5585 traceback when the User name is mentioned in the Access list

CSCuy13937

ASA Watchdog traceback in CP Processing thread during TLS processing

CSCuy21287

STBY ASA does't pass traffic via ASA-IC-6GE-SFP-B ifc after reload

CSCuy32321

Traceback in ldap_client_thread with ldap attr mapping and pw-mgmt

CSCuy34265

ASA Access-list missing and losing elements after configuration change

CSCuy43839

ASA reloads in thread name: DATAPATH while encrypting L2L packet

CSCuy49902

inspect ip-option is not allowing "NOP" even when allowed

CSCuy51918

Buffer overflow in RAMFS dirent structure causing traceback

CSCuy73652

Traceback in thread name idfw when modifying object-group having FQDN

CSCuy74218

Assert Traceback in Thread Name: DATAPATH on clustered packet reassembly

CSCuy78802

orignial master not defending all GARP packets after cluster split brain

CSCuy85243

ASA traceback when receive Radius attribute with improper variable type

CSCuy96391

ASA clientless rewriter failure at 'CSCOPut_hash' function

CSCuz10371

ASA Traceback and reload by strncpy_sx.c

CSCuz21068

CSCOPut_hash can initiate unexepected requests

 

 

Revision:  Version 9.2(4)8 – 02/26/2016

Files:  asa924-8-smp-k8.bin

Defects resolved since 9.2(4)5:

 

CSCur21069

Cisco ASA Failover Command Injection Vulnerability

CSCur51051

LU allocate connection failed on the Standby ASA unit

CSCus10787

Transactional ACL commit will bypass security policy during compilation

CSCus53126

ASA traffic not sent properly using 'traffic-forward sfr monitor-only'

CSCus85257

ASA Connector - Provide Higher Layer Health Checks for CWS Tower

CSCut03981

ASA SSLVPN Client cert validation failure - SSL Lib error: Bad RSA Sig

CSCut40770

Interface TLV to SFR is corrupt when frame is longer than 2048 bytes

CSCuu48197

ASA: Stuck uauth entry rejects AnyConnect user connections

CSCuv09538

ASA: CLI commands not showing help(?) options for local authorization

CSCuv20449

Traceback in Thread Name: ssh when using capture or continuous ping

CSCuv51649

SSL : Unable to Join nodes in Cluster

CSCuv70932

FO: ASAv traceback while syncing during upgrade from 9.4.1 to 9.5.1

CSCuw19671

ASA traceback while restoring backup configuration from ASDM

CSCuw24664

ASA:Traceback in Thread Name:- netfs_thread_init

CSCuw44038

Watchdog traceback in ldap_client_thread with large number of ldap grps

CSCuw87331

ASA: Traceback in Thread name DATAPATH-7-1918

CSCuw92005

Thread Name: DATAPATH-17-3095: Unit reboots when joining cluster

CSCux07002

ASA: assertion "pp->pd == pd" failed: file "main.c", line 192

CSCux20178

OSPF neighbor goes down after "reload in xx" commnad in 9.2 and later

CSCux23659

ASA 9.1.6.10 traceback after remove compact flash and execute dir cmd

CSCux26443

DAP URL-List Command Says It Supports 491 Characters; Only Supports 245

CSCux37303

Port-Channel Config on Gi 0/0 causes Boot Loop - FIPS related

CSCux37442

Cisco signed certificate expired for WebVpn Port Forward Binary on ASA

CSCux41145

Evaluation of pix-asa for OpenSSL December 2015 Vulnerabilities

CSCux45179

SSL sessions stop processing -"Unable to create session directory" error

CSCux56111

"no ipv6-vpn-addr-assign" CLI not working

CSCux58016

AnyConnect sessions fail due to IPv6 address assignment failure.

CSCux59122

ASA L7 policy-map comes into affect only if the inspection is re-applied

CSCux61257

ASA: Traceback in Thread IP Address Assign

CSCux72610

ASA TACACS+: process tacplus_snd uses large percentage of CPU

CSCux81683

ASA Traceback on Thread Name: Unicorn Admin Handler

CSCux85725

ASA WebVPN: Java RDP Plugin does not launch

CSCux87457

ASA traceback in Thread  Name: https_proxy

CSCux88237

ASA traceback in DATAPATH thread

CSCuy01420

ASA traceback in Thread Name: Unicorn Proxy Thread.

CSCuy03024

ASA traceback and reload citing Thread Name: idfw_proc

CSCuy28710

ARP source IP sanity check against proxy-arp list

CSCuy32321

Traceback in ldap_client_thread with ldap attr mapping and pw-mgmt

CSCuy41986

OCSP validation fails when multiple certs in chain are verified

 

 

Revision:  Version 9.2(4)5 – 01/14/2016

Files:  asa924-5-smp-k8.bin

Defects resolved since 9.2(4)4:

 

CSCux29978

Cisco ASA IKEv1 and IKEv2 Buffer Overflow Vulnerability

 

CSCux42019

Cisco ASA IKEv1 and IKEv2 Buffer Overflow Vulnerability

 

 

Revision:  Version 9.2(4)4 – 12/14/2015

Files:  asa924-4-smp-k8.bin

Defects resolved since 9.2(4)2:

 

CSCtx43501

CPU hog due to snmp polling of ASA memory pool information

CSCui20213

5585 interface counters show 0 for working interfaces and console errors

CSCuo08193

Traceback in Thread Name: DATAPATH-1-1382 while processing nat-t packet

CSCur07369

SXP Version Mismatch Between ASA & N7K with clustering

CSCus16416

Share licenses are not activated on failover pair after power cycle

CSCus34033

ASA fails to pass ipv6 address to anyconnect client when using RADIUS

CSCut40770

Interface TLV to SFR is corrupt when frame is longer than 2048 bytes

CSCut67779

Investigate impact of jumbo-frame reservation on low-end ASA platforms

CSCut71095

ASA WebVPN clientless cookie authentication bypass

CSCuu88412

When > 510 characters entered in CLI, context switches to admin/system

CSCuu91304

Immediate FIN from client after GET breaks scansafe connection

CSCuv38654

rewriter returns 302 for a file download

CSCuv49446

ASA traceback on Standby device during config sync in thread DATAPATH

CSCuv50709

Standby ASA inside IP not reachable after Anyconnect disconnect

CSCuv66333

ASA picks incorrect trustpoint to verify OCSP Response

CSCuv87150

ASA traceback in Thread Name: fover_parse (ak47/ramfs)

CSCuv92371

ASA traceback: SSH Thread: many users logged in and dACLs being modified

CSCuv92384

ASA TCP Normalizer sends PUSH ACK for invalid ACK for half-open CONNS

CSCuv94338

ASA traceback  in Thread  Name: CP Crypto Result Processing.

CSCuw02009

ASA - SSH sessions stuck in CLOSE_WAIT causing ASA to send RST

CSCuw14334

Trace back with Thread Name: IP Address Assign

CSCuw16607

ASA EIGRP does not send poison reverse for neighbors to remove route

CSCuw17930

Improper S2S IPSec Datapath Selection for Remote Overlapping Networks

CSCuw22130

ASA traceback when removing dynamic PAT statement from cluster

CSCuw28735

Cisco ASA Software Version Information Disclosure Vulnerability

CSCuw36853

ASA: ICMP error loop on cluster CCL with Interface PAT

CSCuw41548

DNS Traceback in channel_put()

CSCuw66397

DHCP Server Process stuck if dhcpd auto_config already enabled from CLI

CSCuw87910

PCP 10.6 Clientless VPN Access is Denied when accessing Pages

CSCux09310

ASA traceback when using an ECDSA certificate

 

 

Revision:  Version 9.2(4)2 – 10/09/2015

Files:  asa924-2-smp-k8.bin

Defects resolved since 9.2(4):

 

CSCtr84992

Possible to add multiple identical lines under certificate maps

CSCuq97035

WEBVPN: Citrix 5/6 application doesn't launch with IE10/Windows 7

CSCur09141

RRI static routing changes not updated in routing table

CSCus63269

HTTP redirect to the VPNLB address using HTTPS fails in 9.1.5

CSCut49034

ASA: High CPU on standby due to RDP conn to AC client from CL SSL portal

CSCut64327

L2TP/IPsec traffic dropped due to "vpn-overlap-conflict"

CSCut95793

ASA: Anyconnect IPv6 Traceroute does not work as expected

CSCuu18989

ASA %ASA-3-201011: Connection limit exceeded when not hitting max limit

CSCuu25430

Object nat rule is not matched

CSCuu52976

ASA not checking the MAC of the TLS records

CSCuu53928

ASA does not set forward address or p-bit in OSPF redistrubution in NSSA

CSCuu61573

9.5.2 Gold Setup - Traceback in DATAPATH-6-2596 snp_fp_get_frag_chain

CSCuu63656

ASA not generating PIM register packet for directly connected sources

CSCuu73395

Auth-prompt configured in one context appears in another context

CSCuu75901

ASA failover due to issue show local-host command make CPU-hog

CSCuu78835

Webvpn rewrite issues for Confluence - by atlassian on latest v6.4.5

CSCuu83280

Evaluation of OpenSSL June 2015

CSCuu84697

ASA Traceback in  Thread Name ssh/client

CSCuu86195

conn-max counter is not decreased accordingly

CSCuu87823

ASAv traceback in DATAPATH when used for WebVPN

CSCuu94945

ASA: Traceback while copying file using SCP on ASA

CSCuv01022

ASA:OSPF over L2L tunnels is not working with multiple cry map entries

CSCuv01177

ASA: traceback in IDFW AD agent

CSCuv05386

Clientless webvpn on ASA does not display asmx files

CSCuv07106

ASATraceback in ssh whilst adding new line to extended ACL

CSCuv10258

ASA5505 permanent base license, temp secplus, failover, vlan count issue

CSCuv10938

'redistribute' cmds under 'router eigrp' removed on deleting any context

CSCuv12564

Memory leak @regcomp_unicorn with APCF configured

CSCuv12884

Unable to authenticate with remove aaa-server from different context

CSCuv30184

AddThis widget is not shown causing Traceback in Unicorn Proxy Thread

CSCuv32615

ASA: LDAP over SSL Authentication failure

CSCuv39775

ASA cluster-Incorrect "current conns" counter in service-policy

CSCuv42413

Dynamic Route Not Installed After Failover

CSCuv45756

ASA may tracebeck when displaying packet capture with trace option

CSCuv57389

ASA PKI: cert auth fails after upgrade to 9.1(6.4) / 9.1(6.6) / 9.1(6.8)

CSCuv58559

Traceback in Thread Name: DATAPATH on modifying "set connection" in MPF

CSCuv70576

ASA: 1550 block depletion to due to L2L VPN traffic

CSCuv79552

Standby traceback during config replication with customization export

CSCuv87760

Unicorn proxy thread traceback with RAMFS processing

CSCuv91730

Request allow packets to pass when snort is down for ASA configurations

CSCuv96011

OSPF over IKEv2 L2L tunnel is broken on ASA with 9.2.1 onwards

CSCuw00971

ASA truncates url-redirect at 160 chars for ra vpn clients (ISE 1.3+)

CSCuw09578

ASA 9.3.3.224 traceback in ak47_platform.c  with WebVPN  stress test