Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.4(4)37 – 07/10/2019

Files:  asa944-37-smp-k8.bin

Defects resolved since 9.4(4)36:

 

CSCvm50421

ASA traceback on slave/standby during sync config due to OSPF/EIGRP and IPv6 used together in ACE

 

  

Revision:  Version 9.4(4)36 – 05/10/2019

Files:  asa944-36-smp-k8.bin

Defects resolved since 9.4(4)34:

 

CSCvo77038

ASDM launcher download not working on Safari browser

CSCvo87930

HTTP with ipv6 using w3m is failing

CSCvp36425

ASA 5506/5508/5516 traceback in Thread Name octnic_hm_thread

 

 

Revision:  Version 9.4(4)34 – 03/29/2019

Files:  asa944-34-smp-k8.bin

Defects resolved since 9.4(4)32:

 

CSCvo87930

HTTP with ipv6 using w3m is failing

 

Caution: If you are using CSM, and you upgrade to ASA Version 9.4(4)34 or later, then you must upgrade CSM to Version 4.19 or later. Earlier versions of CSM are not compatible.

 

 

Revision:  Version 9.4(4)32 – 03/13/2019

Files:  asa944-32-smp-k8.bin

Defects resolved since 9.4(4)28:

 

CSCvj01704

ASA is getting traceback with reboot only on Spyker aftr shutdown SFR module

CSCvm53531

Cisco Adaptive Security Appliance Software Privilege Escalation Vulnerability

CSCvn78174

traceback on inspect_process

CSCvo63240

Smart Tunnel bookmarks don't work after upgrade giving certificate error

 

 

Revision:  Version 9.4(4)28 – 12/19/2018

Files:  asa944-28-smp-k8.bin

Defects resolved since 9.4(4)27:

 

CSCvm53531

PIX-ASA rest-api unauthorized access.

 

 

Revision:  Version 9.4(4)28 – 11/19/2018

Files:  asa944-28-smp-k8.bin

Defects resolved since 9.4(4)27:

 

CSCvg82650

RDP session does not establish after changing SSL certificate on ASA.

CSCvi42008

Stuck uauth entry rejects AnyConnect user connections

CSCvk66771

The CPU profiler stops running without having hit the threshold and without collecting any samples.

CSCvm78449

Unable to modify access control license entry with log default command

CSCvm78458

ASA traceback on ASA5516 during boot due to "out of stack memory" prior to disk initialization

CSCuy57310

Cisco Adaptive Security Appliance Traffic Flow Confidentiality Denial of Service Vulnerability

 

 

Revision:  Version 9.4(4)27 – 11/06/2018

Files:  asa944-27-smp-k8.bin

Defects resolved since 9.4(4)25:

 

CSCvm43975

Cisco Adaptive Security Appliance Software and FTD Software Denial of Service Vulnerability

 

 

Revision:  Version 9.4(4)25 – 10/17/2018

Files:  asa944-25-smp-k8.bin

Defects resolved since 9.4(4)24:

 

CSCvm80874

Need to update Smart Call Home built-in CA certificate for tools.cisco.com

 

 

Revision:  Version 9.4(4)24 – 10/05/2018

Files:  asa944-24-smp-k8.bin

Defects resolved since 9.4(4)22:

 

CSCvd33004

_lina_assert in createFoverInterface when configuring failover

CSCve95403

ASA boot loop caused by logs sent after FIPS boot test

CSCvg01119

IPV4: Implementing buffered reliability mechanism for routing updates

CSCvi48170

ASA 9.4.4.8, SNMP causing slow memory leak

CSCvj42269

ASA 9.8.2  Receiving syslog 321006 reporting System Memory as 101%

CSCvj47256

ASA SIP and Skinny sessions drop, when two subsequent failovers take place

CSCvj72309

FTD does not send Marker for End-of-RIB after a BGP Graceful Restart

CSCvk36733

mac  address is flapping on huasan switch when  asa etherchannel is configued with active mode

CSCvk67569

ASA unable to handle Chunked Transfer-encoding returned in HTTP response pages in Clientless WebVPN

CSCvk70676

Clientless webvpn fails when  ASA sends HTTP as a message-body

CSCvm56019

Cisco Adaptive Security Appliance WebVPN - VPN not connecting through Browser

 

 

Revision:  Version 9.4(4)22 – 08/22/2018

Files:  asa944-22-smp-k8.bin

Defects resolved since 9.4(4)20:

 

CSCvc79569

mac-address auto command uses default prefix of 1 on ASA5585-X

CSCvg32179

Javascript elements rewriter issue

CSCvh20742

Cisco Adaptive Security Appliance Clientless SSL VPN Cross-Site Scripting Vulnerability

CSCvh83849

DHCP Relay With Dual ISP and Backup IPSEC Tunnels Causes Flapping

CSCvi19220

ASA fails to encrypt after performing IPv6 to IPv4 NAT translation

CSCvi31540

Traceback and reload with 'show tech' on ASA with No Payload Encryption (NPE)

CSCvi37644

PKI:- ASA fails to process CRL's with error "Add CA req to pool failed. Pool full."

CSCvi70606

ASA 9.6(4): WebVPN page not loading correctly

CSCvi97729

To-the-box traffic being routing out a data interface when failover is transitioning on a New Active

CSCvj37924

CWE-20: Improper Input Validation

CSCvj67740

Static IPv6 route prefix will be removed from the ASA configuration

CSCvj95451

webvpn-l7-rewriter: Bookmark logout fails on IE

CSCvj97157

WebPage is not loading due to client rewriter issue on JS files

CSCvk08377

ASA 5525 running 9.8.2.20 memory exhaustion.

CSCvk18378

ASA Traceback and reload when executing show process (rip: inet_ntop6)

CSCvk18578

Enabling compression necessary to load ASA SSLVPN login page customization

CSCvk26887

Certificate import from Local CA fails due to invalid Content-Encoding

CSCvk57516

FTD 6.2.3: Low DMA memory leading to VPN failures due to incorrect crypto maps

 

 

Revision:  Version 9.4(4)20 – 06/19/2018

Files:  asa944-20-smp-k8.bin

Defects resolved since 9.4(4)18:

 

CSCvb29688

Stale VPN Context entries cause ASA to stop encrypting traffic despite fix for CSCup37416

CSCvb52381

OSPF continuously flaps after master change (L2 cluster, multi-ctx)

CSCuv68725

ASA unable to remove ACE with 'log disable' option

CSCve94917

Stale VPN Context issue seen in 9.1 code despite fix for CSCvb29688

CSCvf85065

ASA: Traceback by Thread Name idfw_proc

CSCvg25538

FORWARD PORT: 1550/2048/9344 byte memory block depletion due to identity UDP traffic

CSCvh30261

ASA watchdog traceback during context modification/configuration sync

CSCvh71738

FQDN object are getting resolved after removing access-group configuration

CSCvh91399

upgrade of ASA5500 series firewalls results in boot loop (not able to get past ROMMON)

CSCvh99159

RADIUS authentication/authorization fails for ASDM

CSCvi08450

CWS redirection on ASA doesn't treat SSL Client Hello retransmission properly in specific condition

CSCvi22507

IKEv1 RRI : With Answer-only Reverse Route gets deleted during Phase 1 rekey

CSCvi38151

ASA HA with IPv6: IPv6 static/connected routes are not sync/replicated between Active/Standby pairs.

CSCvi45567

Not able to do snmpwalk when snmpv1&2c host group configured.

CSCvi55070

IKEv1 RRI : With Originate-only Reverse Route gets deleted during Phase 1 rekey

CSCvi76577

ASA:netsnmp:Snmpwalk is failed on some group of IPs of a host-group.

CSCvi82779

ASA  generate traceback in DATAPATH thread

CSCvi92430

Blade kernel crash on FPR4140

CSCvi95544

ASA not matching IPv6 traffic correctly in ACL with "any" keyword configured

CSCvj26450

ASA PKI OCSP failing - CRYPTO_PKI: failed to decode OCSP response data.

CSCvj32264

ASA - zonelabs-integrity : Traceback and High CPU due to Process 'Integrity FW task'

CSCvj37448

FPR-ASA : Device sends only ID certificate in SSL server certificate packet after reload

CSCvj48340

ASA memory Leak - snp_svc_insert_dtls_session

 

Revision:  Version 9.4(4)18 – 04/20/2018

Files:  asa944-18-smp-k8.bin

Defects resolved since 9.4(4)17:

 

CSCva92997

9.7.1 traceback in snp_fp_qos

CSCuu67159

ASA: traceback in DATAPATH-2-1157

CSCve20395

ASA Portal Java plug-ins fail with the latest Java updates

CSCvf76013

ASA crash with snp_egress_capture_sgt()

CSCvg05442

ASA traceback due to deadlock between DATAPATH and webvpn processes

CSCvg56122

SSL handshake fails with large certificate chain size

CSCvh13415

ASA:OpenSSL Vulnerabilities CVE-2017-3737 and  CVE-2017-3738

CSCvh28309

ASDM stops working with hostscan enabled. ASDM works with hostscan disabled.

CSCvh47057

ASA - ICMP flow drops with "no-adjacency" on interface configured in zone when inspection enabled

CSCvh54940

ASA traceback with thread name "idfw_proc "

CSCvh73582

traceback related to SIP inspection processing

CSCvh85514

ASA Traceback in Thread Name: Unicorn Proxy Thread

CSCvh90947

ASA traceback with Thread Name: fover_parse

CSCvh91053

ASA sending DHCP decline | not assiging address to AC clients via DHCP

CSCvh95325

Standby ASA traceback during replication from mate 9.2(4)27

CSCvi01312

webvpn: multiple rendering issues on Confluence and Jira applications

CSCvi07636

ASA: Traceback in Thread Name UserFromCert

CSCvi19263

ASA 9.7.1.15 Traceback while releasing a vpn context spin lock

CSCvi33962

WebVPN rewriter: drop down menu doesn't work in BMC Remedy

CSCvi35805

ASA Cut-Through Proxy allowing user to access website, but displaying "authentication failed"

CSCvi58089

Memory leak on webvpn

 

 

Revision:  Version 9.4(4)17 – 02/13/2018

Files:  asa944-17-smp-k8.bin

Defects resolved since 9.4(4)16:

 

CSCvd08983

ASA using TACACS authentication and configured 'password-policy lifetime' will deny access

CSCve78652

ASA Traceback on  Kenton in Thread Name: CTM message handler

CSCvg00265

ASA fails to rejoin the failover HA Or a cluster with insufficient memory error, OGS enabled

CSCvg58385

ASA reports incorrectly double input packets traffic on PPPoe/VPDN interface

CSCvg67135

ASA backs out of connection when it receives Server Key exchange with named curve as x25519

CSCvg81583

Split brain after recovery from interface failure when fover and then data ifc goes down in order.

CSCvg82932

Memory Leaking on ASA with vpnfol_memory_allocate and vpnfol_data_dyn_string_allocator

CSCvg90820

SSPs with ASA in multiple context moves in active-active situation while failover is occurring

CSCvh27703

ASA - Traceback in thread name SSH while applying BGP show commands

CSCvh32323

Memory leak in idfw component on ASA

 

 

Revision:  Version 9.4(4)16 – 02/03/2018

Files:  asa944-16-smp-k8.bin

Defects resolved since 9.4(4)14:

 

CSCvh79732

Cisco Adaptive Security Appliance Denial of Service Vulnerability

CSCvh81870

Memory leak in IKE for aggregate-auth

 

 

Revision:  Version 9.4(4)14 – 12/07/2017

Files:  asa944-14-smp-k8.bin

Defects resolved since 9.4(4)13:

 

CSCvd80721

In security context, cannot generate the SNMP events trap.

CSCvd87211

ASA traceback when trying to remove configured capture

CSCve77049

ASA Memory depletion due to scansafe inspection

CSCvf03676

Ports not getting reserved on ASA after adding snmp configuration.

CSCvf89504

ASA cluster intermittently drop IP fragments when NAT is involved

CSCvg25175

ASA getting stuck in hung state because of STATIC NAT configuration for SNMP ports

CSCvg29692

http-server component of ASA is not closing connections

CSCvg35618

Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability

CSCvg40155

Cisco ASA Virtual Private Network SSL Client Certificate Bypass Vulnerability

CSCvg51984

High CPU in IKE Daemon causing slow convergence of VPN tunnels in a scaled environment

CSCvg53981

dir /recursive cache:/stc and "dir cache:stc/2/" list AnyConnect.xsd differently on ASA9.8.2

CSCvg57954

Modifying service object-groups (add and remove objects) removes ACE

 

 

Revision:  Version 9.4(4)13 – 10/26/2017

Files:  asa944-13-smp-k8.bin

Defects resolved since 9.4(4)12:

 

CSCto19051

Resolve any vulnerabilities in ASA/FTD lina Heimdal Kerberos code

CSCuv86562

ASA traceback in thread name fover_health_monitoring_thread

CSCvb53233

ASA 9.1(7)9 Traceback with %ASA-1-199010 and %ASA-1-716528 syslog messages

CSCvd00293

VTI - Some sessions do not get cleared from vpn-sessiondb

CSCvd53381

ASA Traceback when saving/viewing the configuration due to time-range ACLs

CSCve18902

Cisco Adaptive Security Appliance TLS Denial of Service Vulnerability

CSCve34335

Cisco Adaptive Security Appliance TLS Denial of Service Vulnerability

CSCve38446

Cisco Adaptive Security Appliance TLS Denial of Service Vulnerability

CSCve73025

All 1700 "4 byte blocks" were depleted after a weekend VPN load test.

CSCvf10327

ENH: Unique IPv6 link-local addresses assigned when sub-interface is being created

CSCvf22190

ASA memory leak - DTLS sessions

CSCvf28749

ASA not sending register stop when mroute is configured

CSCvf34791

Install 6.2.2-1290 sfr on a ASA with firepower -  asa cores

CSCvf43650

OSPF route not getting installed on peer devices when an ASA failover happens with NSF enabled

CSCvf44142

ASA 9.x: DNS inspection appending "0" on PTR query

CSCvf63108

ASA drops the IGMP Report packet which has Source IP address 0.0.0.0

CSCvf63718

Cisco Adaptive Security Appliance Flow Creation Denial of Service Vulnerability

CSCvf81932

'Incomplete command' error with some inspects due to K7 license

CSCvf83709

Slave kicked out due to CCL link failure and rejoins, but loses v3 user in multiple context mode

CSCvf94973

ASA on FP 2100 traceback when uploading AnyConnect image via ASDM

CSCvg01132

ASA : After upgrading from 9.2(4) to 9.2(4)18 serial connection hangs

CSCvg17478

traceback with Show OSPF Database Commands

 

 

Revision:  Version 9.4(4)12 – 09/18/2017

Files:  asa944-12-smp-k8.bin

Defects resolved since 9.4(4)10:

 

CSCuj98977

ASA Traceback in thread SSH when ran "show service set conn detail"

CSCuv63875

ASA traceback in Thread Name:ci/console while running show ospf commands

CSCvb97470

asa Rest-api - component monitoring - empty value/blank value

CSCve06436

Routes do not sync properly between different minor versions during hitless upgrade

CSCvf17214

ASA Exports ECDSA as corrupted PKCS12

CSCvf22190

ASA memory leak - DTLS sessions

CSCvf28749

ASA not sending register stop when mroute is configured

CSCvf31539

ASA Connections stuck in idle state with DCD enabled

CSCvf54081

TLS version 1.1 connection failed no shared signature algorithms@t1_lib.c:3106

CSCvf54981

ASA - 80 Byte memory block depletion

CSCvf61419

Traceback in thread DATAPATH due to NAT

 

 

Revision:  Version 9.4(4)10 – 08/24/2017

Files:  asa944-10-smp-k8.bin

Defects resolved since 9.4(4)8:

 

CSCvc18200

print the thread name for non-crashing threads in crash info

CSCvc60259

FSCK Files created and stored in flash with incorrect timestamp of Jan 01 1980 03:00:00

CSCvc96614

ASA: IKEv2 ipsec-proposal command removed if more than 9 proposals configured in single command

CSCvd01130

ASA TCP SIP inspection translation not working when IP phone is behind VPN tunnel

CSCve02469

ASA Issue with bgp route summarization(auto-summary)and route advertisement

CSCve09249

ASA: Active FTP not working with extended keyword in NAT.

CSCve18293

ASA traceback observed in datapath

CSCve28027

Calls not working with CUCI Lync version 11.6.3 on ASA

CSCve37948

ASA does not install routes learned via OSPF over IPSec using UDP/4500

CSCve46883

FTD Diagnostic Interface does Proxy ARP for br1 management subnet

CSCve47393

OSPF Rogue LSA with maximum sequence number vulnerability

CSCve57150

vpn vlan mapping issue

CSCve60829

ASA Cluster : Potential UDP loop on cluster link with PAT pool

CSCve63762

ASASM: Interface vlans going to admin down after reload.

CSCve72227

IPsec SA fail to come up and flap with more than 1000 IPsec SA count in ASA5506/5508/5516

CSCve77440

Traceback in Unicorn Proxy Thread due to Webvpn

CSCve78986

ASA/ 9.6.3 // WebVPN Smart tunnel works but floods windows with event viewer

CSCve94886

Traceback on ASA with Firepower Services during NAT rule changes and packet capture enabled

CSCvf01762

Evaluation for the vulnerabilities CVE-2017-1000364 and CVE-2017-1000366

CSCvf01873

Regex is not matching for HTTP argument field

CSCvf07075

ASA - Crypto accelerator traceback in a loop

CSCvf16142

ASA-5-720012:(VPN-Secondary)Failed to update IPSec failover runtime data in ASA cluster environment

CSCvf16429

Ikev2 Remote Access client sessions stuck in Delete state

CSCvf24063

ASA5585 traceback in DATAPATH - snp_vpn_process_natt_pkt

CSCvf24387

EC Certificates that are imported to the ASA in PKCS12s cannot be used for SSL

CSCvf41547

traceback in watchdog process

 

 

Revision:  Version 9.4(4)8 – 07/17/2017

Files:  asa944-8-smp-k8.bin

Defects resolved since 9.4(4)6:

 

CSCuw37752

FTP data conn scaling fails with dynamic PAT

CSCuz52474

Evaluation of pix-asa for OpenSSL May 2016

CSCuz72137

ASA dropping packets with "novalid adjacency" though valid ARP entry avail

CSCva92997

9.7.1 traceback in snp_fp_qos

CSCvb75685

EZVPN NEM client can't reconnect after "no vpnclient enable" is entered

CSCvc07112

Implement detection and auto-fix capability for scheduler corruption problems

CSCvc82270

ASA 1550 block gradual depletion

CSCvc83462

gzip compression not working via Webvpn

CSCvc85369

ASA does not respond to IPv6 MLD Query.

CSCvd35811

Traceback in thread name DATAPATH

CSCvd50107

ASA traceback in Thread name: idfw_proc on running "show access-list", while displaying remark

CSCvd58321

Web folder filebrowser applet code signing certificate expired

CSCvd64416

ASA All contexts use the same EIGRP router-ID upon a reload

CSCvd68518

Traceback in Thread Name: Unicorn Admin Handler

CSCvd71473

ASA: slow memory leak when using many DNS queries

CSCvd79797

ASA local dns resolution fails when dns server is reachable through a site to site ipsec tunnel

CSCvd87647

ASA traceback in Thread Name: fover_parse performing upgrade from 9.1.5 to 9.4.3

CSCvd89003

ASA traceback observed in Datapath due to SIP inspection

CSCvd92423

ASA Traceback in Unicorn Proxy Thread

CSCve02854

SFR Backplane is pulling the public address for policy match instead of ASA inside address

CSCve04326

Slave should have use CCL to forward traffic instead of blackholing when egress interface is down

CSCve06367

Show Crypto Acclerator shows status as booting for hardware devices

CSCve08664

Dist-S2S: tunnels stay up even after passing vpn idle timeout in Multimode

CSCve08947

In multi-context ASA drops traffic sourced from certain ports when interface PAT is used

CSCve13410

Upgrading the ASA results in No Valid adjacency due to track configure on the route

CSCve14758

Standby ASA not learning routes via RIP

CSCve15873

ASA: Multicast packets getting dropped starting code 9.6.3

CSCve20346

ASA SNI connection fails after upgrade - no shared cipher

CSCve23033

ICMP Unreachables (PMTU) dropped indicating "Routing failed to locate next hop"

CSCve23091

Auto-RP packet is dropped due to no-route - No route to host

CSCve23784

ASA may traceback on displaying access-list config or saving running config

CSCve31880

network_udpmod_get not releasing shr_lock in rare error case

CSCve42583

ASA: IPv6 protocol X rule for passing through FW is dropping packets with Invalid IP length message

CSCve57375

CPU hog in CP Processing thread due to huge number of sunrpc sessions

CSCve57548

ASA- Traceback in 'Thread Name : Datapath' on crypto_SSL functions

CSCve72155

Memory leak at location "snp_fp_encrypt" when syslog server is reachable over the VPN tunnel

CSCve73556

ASA traceback on websns_rcv_tcp

CSCve91068

Cisco Adaptive Security Appliance HREF Cross Site Scripting Vulnerability

 

 

Revision:  Version 9.4(4)6 – 05/05/2017

Files:  asa944-6-smp-k8.bin

Defects resolved since 9.4(4)5:

 

CSCuj69650

ASA block new conns with logging permit-hostdown & TCP syslog is down

CSCuy91405

ASA should not load-balance same flow traffic over port-channel CCL

CSCuz77293

OSPF multicast filter rules missing in cluster slave

CSCvc24380

Traceback on thread name IKE Daemon at mqc_enable_qos_for_tunnel

CSCvc56526

CEP records edit page take minutes to load

CSCvc61818

CTP after failed attempt sends the domain along with the username

CSCvd15843

Port Forwarding Session times out due to vpn-idle-timeout in group-policy while passing data

CSCvd24066

ASA drops web traffic when IM inspection is enabled.

CSCvd43309

Access-lists not being matched for a newly created object-group

CSCvd49262

Traceback when trying to save/view access-list with giant object groups (display_hole_og)

CSCvd50389

RT#687120: Bookmark Issue with clientless VPN - SAML

CSCvd53884

Firepower (SFR) module data plane down after reload of module

CSCvd54680

ASA: TLS-proxy - Traceback with thread name - Dispatch Unit

CSCvd55115

ASA in cluster results in incorrect user group mappings between the Master and Slave

CSCvd55983

Traceback in Thread Name: dhcp_daemon

CSCvd55999

%ASA-3-216001: internal error in ci_cons_shell: thread data misuse

CSCvd58417

DCERPC inspection drops packets and breaks communication

CSCvd59063

Cisco Adaptive Security Appliance Authentication Denial of Service Vulnerability

CSCvd62509

ASA traceback in Thread Name: accept/http when ASDM is displaying Access Rules

CSCvd65797

ASA May crash when changing a NAT related object to fqdn

CSCvd66303

Error deploying ASAv on ESXi vCenter 6.5

CSCvd76939

ASA policy-map configuration is not replicated to cluster slave

CSCvd99476

The interactive icons on internal bookmark site not showing properly (+CSCO+0undefined)

CSCvd99859

ASA may drop DNS reply containing only additional RR of type TXT

CSCve05841

ASA reloaded while joining cluster and active as slave

 

 

Revision:  Version 9.4(4)5 – 04/03/2017

Files:  asa944-5-smp-k8.bin

Defects resolved since 9.4(4)2:

 

CSCut09459

incorrect failover status for contexts via SNMP

CSCvb92548

ASA matches incorrect ACL with object-group-search enabled

CSCvc55674

ASA: IPSec SA failed to come up

CSCvc58272

ASA incorrectly processing negative numbers in wrappers, resulting in graphical webvpn issue

CSCvc60254

SIP: 200 OK messages with multiple seqments not reassembled correctly

CSCvc85369

ASA does not respond to IPv6 MLD Query.

CSCvc87914

ASA traceback and Reload on Config Sync Failure

CSCvc88411

1550-byte block depletion seen due to Radius Accounting packets

CSCvd01736

L2TP connects only sometimes when DHCP used

CSCvd06022

ASA-FP9300 Crashed in thread name IPSEC MESSAGE HANDLER after upgrade

CSCvd08200

Slow Memory leak in ASA

CSCvd21154

5585 does not unbundle its data intfs for 30 seconds after leaving cluste

CSCvd21541

Cannot delete port-object once created under the Service object group in ASA 944

CSCvd23016

ASA may traceback when copying capture out using tftp

CSCvd23471

ASA may traceback while loading a large context config during bootup

CSCvd28859

ASA: PBR Memory leak for ICMP traffic

CSCvd39113

Cluster C-Hash table is updated with one more unit despite the new unit didn't join the setup

CSCvd78303

ARP functions fail after 213 days of uptime, drop with error 'punt-rate-limit-exceeded'

 

 

Revision:  Version 9.4(4)2 – 02/20/2017

Files:  asa944-2-smp-k8.bin

Defects resolved since 9.4(4):

 

CSCum28756

ASA: Auth failures for SNMPv3 polling after unit rejoins cluster

CSCut07712

ASA - TO the box traffic break due to int. missing in asp table routing

CSCuv61791

CWS redirection on ASA may corrupt sequence numbers with https traffic

CSCuw88759

ASA: Protocol and Status showing UP without connecting the interface

CSCuz86289

USGv6 Cert: Non-RH0 Packets Being Dropped w/Valid Policy-Map

CSCva22048

ASA: SIP Call Drops with PAT when same media port used in multiple calls

CSCva35990

Traceback on CP Process with H323 inspection, rip h323_service_early_msg

CSCva47608

SCTP MH:pin hole removed and added freq on standby with dual nat

CSCva71783

ICMP error packets in response to reply packets are dropped

CSCva92975

ASA 5585-60 dropping out of cluster with traceback

CSCva97863

971 EST - Console hang on show capture

CSCvb15265

ASA Page fault traceback in Thread Name: DATAPATH

CSCvb43120

ASA Traceback in Checkheaps Thread

CSCvb47006

ASA traceback observed on auto-update thread.

CSCvb52157

viewer_dart.js file not loading correctly

CSCvb78614

4GE-SSM RJ45 interface may drop traffic due to interface "rate limit drops"

CSCvb87586

Failed to ssh management interface after failover and plug-in/out

CSCvb92125

ASA drops DNS PTR Reply with reason Label length exceeded during rewrite

CSCvb92823

ASA SIP inspection may delay transmission of 200 OK when embedded with NOTIFY

CSCvc00689

ASA : memory leak due to ikev2

CSCvc05005

ASA cluster TCP/SSL ports are not displayed on LISTEN state

CSCvc05233

ASA Kenton: DSCP Markings Not Copied to Outer IP Header With IPsec Encapsulation

CSCvc07330

ASAv traceback randomly

CSCvc14448

9.6.2 - Traceback during AnyConnect IKEv2 Performance Test

CSCvc14502

ASA multicontext disallowing new conns with TCP syslog unreachable and logging permit-hostdown set

CSCvc19318

ASA traceback at Thread Name: sch_syslog

CSCvc22193

DSCP Markings Not Copied to Outer IP Header With IPsec Encapsulation

CSCvc25281

Error synchronizing the SNMPv3 user after rebooting a cluster unit

CSCvc25409

ASA memory leak in CloneOctetString when using SNMP polling

CSCvc33796

Implement speed improvements for ACL and NAT table compilation

CSCvc36535

ASA traceback in Thread Name: ssh, rip igb_disable_rx_queues after no shutdown of interface

CSCvc37557

SSL connection hangs between ASA and backend server in clientless WebVPN

CSCvc38425

ASA with FirePOWER module generates traceback and reloads

CSCvc44240

ASA clustering: mac-address cmd is ignored on spanned port-channel interface in 9.6.2

CSCvc48640

ASA not update access-list dynamically when forward-reference enable is configured

CSCvc52072

Webvpn portal not displayed corrrectly for connections landing on default webvpn group.

CSCvc52272

ASA inspection-MPF ACL changes are not getting ordered correctly in the ASP Table

CSCvc52504

ASA may traceback with Thread Name: Unicorn Admin Handler

CSCvc52879

Reloading Active unit in Active/Standby ASA failover pair is not triggering a failover.

CSCvc55974

ikev2 handles get leaked in a L2L setup

CSCvc60964

ASA L3 Cluster: DHCP relay drops DHCPOFFER in case of asymmetric routing

CSCvc62252

Tracking route is up while the reachability is down

CSCvc62556

Traceback in ASA Cluster Thread Name: qos_metric_daemon

CSCvc79371

ASA nat pool not getting updated correctly.

CSCvc79454

Unable to configure ssh public auth for script users

CSCvc82146

ASA traceback in threadname Datapath

CSCvc93947

ASA(9.1.7.12):Connection entries created for multicast streams through standby ASA.

CSCvd03343

Unable to configure SSH public key auth for non-system contexts