Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.6(3)20 – 11/28/2017

Files:  asa963-20-smp-k8.bin

Defects resolved since 9.6(3)17:

 

CSCvd87211

ASA traceback when trying to remove configured capture

CSCve85572

ASA should have a syslog message showing which side closed the connection

CSCvf25666

An ASA with low free memory fails to join existing cluster and could traceback and reload

CSCvf44142

ASA 9.x: DNS inspection appending "0" on PTR query

CSCvf77377

Hostscan: Errors in cscan.log downloading Microsoft and Panda .dll files

CSCvf89504

ASA cluster intermittently drop IP fragments when NAT is involved

CSCvf90278

ASA/FTD traceback when clearing capture - assertion "0" failed: file "mps_hash_table_debug.c"

CSCvf94973

ASA on FP 2100 traceback when uploading AnyConnect image via ASDM

CSCvg01132

ASA : After upgrading from 9.2(4) to 9.2(4)18 serial connection hangs

CSCvg09778

ASA-SSP HA reload in CP Processing due to DNS inspect

CSCvg17478

traceback with Show OSPF Database Commands

CSCvg20796

ASA local DNS resolution fails when DNS server is reachable over a site to site sec VPN tunnel

CSCvg25694

Assert Traceback, thread name : cli_xml_server

CSCvg35618

Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability

CSCvg45952

ASA traceback: thread name scansafe

CSCvg51984

High CPU in IKE Daemon causing slow convergence of VPN tunnels in a scaled environment

CSCvg52995

Unable to save configuration in system context after enabling password encryption in ASA

 

 

Revision:  Version 9.6(3)17 – 10/20/2017

Files:  asa963-17-smp-k8.bin

Defects resolved since 9.6(3)14:

 

CSCto19051

Resolve any vulnerabilities in ASA/FTD lina Heimdal Kerberos code

CSCvb53233

ASA 9.1(7)9 Traceback with %ASA-1-199010 and %ASA-1-716528 syslog messages

CSCvb97470

asa Rest-api - component monitoring - empty value/blank value

CSCvd00293

VTI - Some sessions do not get cleared from vpn-sessiondb

CSCvd53381

ASA Traceback when saving/viewing the configuration due to time-range ACLs

CSCvd97249

Cisco Firepower Detection Engine SSL Decryption Memory Consumption Denial of Service Vulnerability

CSCve06436

Routes do not sync properly between different minor versions during hitless upgrade

CSCve72964

Traceback in DATAPATH-1-2084 ASA 9.(8)1

CSCve73025

All 1700 "4 byte blocks" were depleted after a weekend VPN load test.

CSCve94886

Traceback on ASA with Firepower Services during NAT rule changes and packet capture enabled

CSCve97874

ASA: Low free  DMA Memory on versions  9.6 and later

CSCvf10327

ENH: Unique IPv6 link-local addresses assigned when sub-interface is being created

CSCvf17214

ASA Exports ECDSA as corrupted PKCS12

CSCvf28749

ASA not sending register stop when mroute is configured

CSCvf34791

Install 6.2.2-1290 sfr on a ASA with firepower -  asa cores

CSCvf43650

OSPF route not getting installed on peer devices when an ASA failover happens with NSF enabled

CSCvf54981

ASA - 80 Byte memory block depletion

CSCvf56917

ASA doesn't send LACP PDU during port flap in port-channel

CSCvf57908

Transparent Firewall: Ethertype ACLs installed with incorrect DSAP value

CSCvf61419

Traceback in thread DATAPATH due to NAT

CSCvf63108

ASA drops the IGMP Report packet which has Source IP address 0.0.0.0

CSCvf74218

ASAv image in AWS GovCloud not working in Hourly Billing Mode

CSCvf81222

Memory leak in 112 byte bin when packet hits PBR and connection is built

CSCvf81932

'Incomplete command' error with some inspects due to K7 license

CSCvf82733

crypto ikev1 enable command not installed on FTD CLI

CSCvf83709

Slave kicked out due to CCL link failure and rejoins, but loses v3 user in multiple context mode

CSCvf85065

ASA: Traceback by Thread Name idfw_proc

CSCvf87899

ASA - rare scheduler corruption causes console lock

 

 

Revision:  Version 9.6(3)14 – 09/01/2017

Files:  asa963-14-smp-k8.bin

Defects resolved since 9.6(3)12:

 

CSCuj98977

ASA Traceback in thread SSH when ran "show service set conn detail"

CSCuv63875

ASA traceback in Thread Name:ci/console while running show ospf commands

CSCvc18200

print the thread name for non-crashing threads in crash info

CSCve02469

ASA Issue with bgp route summarization(auto-summary)and route advertisement

CSCve53582

SSH Connections to ASA fail with SLA monitoring & nonzero floating-conn timeout

CSCve77440

Traceback in Unicorn Proxy Thread due to Webvpn

CSCvf07075

ASA - Crypto accelerator traceback in a loop

CSCvf11695

Traceback: Duplicate host entries in flow-export action cause crash after policy deployment

CSCvf14391

multicast traffic sourced from anyconnect pool dropped due to reverse path checked.

CSCvf16142

ASA-5-720012:(VPN-Secondary)Failed to update IPSec failover runtime data in ASA cluster environment

CSCvf24063

ASA5585 traceback in DATAPATH - snp_vpn_process_natt_pkt

CSCvf31539

ASA Connections stuck in idle state with DCD enabled

CSCvf38655

ASA crash in fover_parse after version up

CSCvf41547

traceback in watchdog process

CSCvf46732

Contexts are missing on ASA once Chassis reloads after becoming Master on 9.6 code

CSCvf54081

TLS version 1.1 connection failed no shared signature algorithms@t1_lib.c:3106

CSCvf56506

ASA 9.6(2), 9.6(3) traceback in DataPath

CSCvf76281

IKEv2 RA cert auth. Unable to allocate new session. Max sessions reached

 

 

Revision:  Version 9.6(3)12 – 08/11/2017

Files:  asa963-12-smp-k8.bin

Defects resolved since 9.6(3)11:

 

CSCve94886

Traceback on ASA with Firepower Services during NAT rule changes and packet capture enabled

CSCvf44950

iOS and OS X IKEv2 Native Clients unable to connect to ASA with EAP-TLS

 

 

Revision:  Version 9.6(3)11 – 08/08/2017

Files:  asa963-11-smp-k8.bin

Defects resolved since 9.6(3)9:

 

CSCuw37752

FTP data conn scaling fails with dynamic PAT

CSCuz72137

ASA dropping packets with "novalid adjacency" though valid ARP entry avail

CSCva74756

OSPF Rogue LSA with maximum sequence number vulnerability

CSCvb44254

ASA 5506-X Firepower Threat Defense Reset Button

CSCvb91810

ASA - Incorrect interface-based route-lookup if more specific route exist out different interface

CSCvc60259

FSCK Files created and stored in flash with incorrect timestamp of Jan 01 1980 03:00:00

CSCvc85369

ASA does not respond to IPv6 MLD Query.

CSCvc96614

ASA: IKEv2 ipsec-proposal command removed if more than 9 proposals configured in single command

CSCvd01130

ASA TCP SIP inspection translation not working when IP phone is behind VPN tunnel

CSCvd92423

ASA Traceback in Unicorn Proxy Thread

CSCve06367

Show Crypto Acclerator shows status as booting for hardware devices

CSCve08898

Memory leak with capture with trace and clear capture

CSCve09249

ASA: Active FTP not working with extended keyword in NAT.

CSCve14758

Standby ASA not learning routes via RIP

CSCve18293

ASA traceback observed in datapath

CSCve24088

Smart Licensing ID cert renewal failure should not deregister product instance

CSCve28027

Calls not working with CUCI Lync version 11.6.3 on ASA

CSCve37948

ASA does not install routes learned via OSPF over IPSec using UDP/4500

CSCve42460

NSF IETF/CISCO commands getting removed on reload

CSCve44561

ASA sends the ICMP unreachable type 3 code 4 in the wrong direction when SFR redirection enabled

CSCve46883

FTD Diagnostic Interface does Proxy ARP for br1 management subnet

CSCve47393

OSPF Rogue LSA with maximum sequence number vulnerability

CSCve57150

vpn vlan mapping issue

CSCve57375

CPU hog in CP Processing thread due to huge number of sunrpc sessions

CSCve58709

ASA 9.5.1 onwards, Traffic incorrectly routed instead of management interface

CSCve60829

ASA Cluster : Potential UDP loop on cluster link with PAT pool

CSCve61284

ASA Log message 414003 may be generated with bogus IP data when TCP Syslog Server down

CSCve63762

ASASM: Interface vlans going to admin down after reload.

CSCve72155

Memory leak at location "snp_fp_encrypt" when syslog server is reachable over the VPN tunnel

CSCve72227

IPsec SA fail to come up and flap with more than 1000 IPsec SA count in ASA5506/5508/5516

CSCve73556

ASA traceback on websns_rcv_tcp

CSCve78986

ASA/ 9.6.3 // WebVPN Smart tunnel works but floods windows with event viewer

CSCve91068

Cisco Adaptive Security Appliance HREF Cross Site Scripting Vulnerability

CSCve95969

Unable to scale the flash virtualisation feature up to 250 contexts

CSCve97831

CDA agent stucks in 'Probing' when domain-lookup is enable

CSCvf01762

Evaluation for the vulnerabilities CVE-2017-1000364 and CVE-2017-1000366

CSCvf01873

Regex is not matching for HTTP argument field

CSCvf16429

Ikev2 Remote Access client sessions stuck in Delete state

CSCvf24387

EC Certificates that are imported to the ASA in PKCS12s cannot be used for SSL

 

 

Revision:  Version 9.6(3)9 – 07/19/2017

Files:  asa963-9-smp-k8.bin

Defects resolved since 9.6(3)8:

 

CSCve15873

ASA: Multicast packets getting dropped starting code 9.6.3

CSCve20346

ASA SNI connection fails after upgrade - no shared cipher

CSCve23033

ICMP Unreachables (PMTU) dropped indicating "Routing failed to locate next hop"

CSCve29989

ASA - Traceback in DATAPATH during PAT pool socket allocation

CSCve42583

ASA: IPv6 protocol X rule for passing through FW is dropping packets with Invalid IP length message

 

 

Revision:  Version 9.6(3)8 – 06/22/2017

Files:  asa963-8-smp-k8.bin

Defects resolved since 9.6(3)3:

 

CSCuy48364

ASA 'show memory' output may not properly report total available memory in 9.5(2) and later

CSCuz52474

Evaluation of pix-asa for OpenSSL May 2016

CSCuz72137

ASA dropping packets with novalid adjacency though valid ARP entry avail

CSCva67548

STS:BS - Cluster is disabled because chassis-blade out-of-sync detected

CSCva92997

9.7.1 traceback in snp_fp_qos

CSCvb75685

EZVPN NEM client can't reconnect after no vpnclient enable is entered

CSCvb81438

TCP connections might fail through a FTD cluster with inline mode interfaces

CSCvc56526

CEP records edit page take minutes to load

CSCvc56919

Traffic drops for reverse UDP/TCP IPv6 traffic over IPv4 tunnel

CSCvc82270

ASA 1550 block gradual depletion

CSCvc83462

gzip compression not working via Webvpn

CSCvd20013

Traceback in Thread Name: IPsec message handler on EZVPN client

CSCvd26699

ASA erroneously triggers syslog ID 201011

CSCvd35811

Traceback in thread name DATAPATH

CSCvd50107

ASA traceback in Thread name: idfw_proc on running show access-list, while displaying remark

CSCvd55115

ASA in cluster results in incorrect user group mappings between the Master and Slave

CSCvd55999

%ASA-3-216001: internal error in ci_cons_shell: thread data misuse

CSCvd58094

ASA traceback in ARP thread, PBR configured

CSCvd58321

Web folder filebrowser applet code signing certificate expired

CSCvd68518

Traceback in Thread Name: Unicorn Admin Handler

CSCvd71473

ASA: slow memory leak when using many DNS queries

CSCvd79797

ASA local dns resolution fails when dns server is reachable through a site to site ipsec tunnel

CSCvd79863

FTD OSPF with ECMP, packets are sent to peer in down state for existing connections

CSCvd80740

FTD-VPN: VPN RRI not getting synced between Master and Slave units

CSCvd82265

Increase memory allocated to rest-agent on ASAv5

CSCvd87647

ASA traceback in Thread Name: fover_parse performing upgrade from 9.1.5 to 9.4.3

CSCvd89003

ASA traceback observed in Datapath due to SIP inspection

CSCvd89925

Unable to switch standby unit of the failover pair to active

CSCvd90096

WebVPN forces IE to use IE8 mode

CSCvd97568

FTD traceback observed during failover synchronization.

CSCvd99476

The interactive icons on internal bookmark site not showing properly (+CSCO+0undefined)

CSCvd99859

ASA may drop DNS reply containing only additional RR of type TXT

CSCve02854

SFR Backplane is pulling the public address for policy match instead of ASA inside address

CSCve03387

Proxy ARP information for SSH NLP NAT is not updating on the FTD upon failover

CSCve03974

ASA with FirePOWER services module generates traceback and reload

CSCve04326

Slave should have use CCL to forward traffic instead of blackholing when egress interface is down

CSCve05841

ASA reloaded while joining cluster and active as slave

CSCve07856

CRL verification fails due to incorrect KU after CSCvd41423

CSCve08664

Dist-S2S: tunnels stay up even after passing vpn idle timeout in Multimode

CSCve08947

In multi-context ASA drops traffic sourced from certain ports when interface PAT is used

CSCve12654

ASA clustering to support rollback feature with CSM

CSCve13410

Upgrading the ASA results in No Valid adjacency due to track configure on the route

CSCve18880

Username is not fetched from certificate when certificate map is used in clientless portal

CSCve19683

FP4100 SSP 9.6.2 / cluster - Tx queue stuck causing traffic drop to occur

CSCve20438

activate-tunnel-group-scripts not available in 9.6.3.1

CSCve23091

Auto-RP packet is dropped due to no-route - No route to host

CSCve23784

ASA may traceback on displaying access-list config or saving running config

CSCve24299

Traceback in Thread Name: IP RIB Update when routes are redistributed

CSCve31809

ASA corrupt dst mac address of return traffic from l2tp client

CSCve31880

network_udpmod_get not releasing shr_lock in rare error case

CSCve34729

ASA interfaces may stop passing traffic after ASA reload with FIPS mode enabled

CSCve43146

AnyConnect new customization creation fails on ASDM for all ASA versions above 9.5(3)

CSCve48105

Slave reports Master's interface status as init while it is up

CSCve50118

ASA Memory Leak - RSA toolkit

CSCve57548

ASA- Traceback in 'Thread Name : Datapath' on crypto_SSL functions

 

 

Revision:  Version 9.6(3)3 – 04/27/2017

Files:  asa963-3-smp-k8.bin

Defects resolved since 9.6(3)1:

 

CSCuj69650

ASA block new conns with "logging permit-hostdown" & TCP syslog is down

CSCuz77293

OSPF multicast filter rules missing in cluster slave

CSCvb28491

Unable to run show counters protocol ip

CSCvc07112

Implement detection and auto-fix capability for scheduler corruption problems

CSCvc24380

Traceback on thread name IKE Daemon at mqc_enable_qos_for_tunnel

CSCvc91839

Unable to deploy policy on FTD devices due to wrong XML parsing

CSCvd08200

Slow Memory leak in ASA

CSCvd14266

ASA traceback in DATAPATH-41-16976 thread

CSCvd15843

Port Forwarding Session times out due to "vpn-idle-timeout" in group-policy while passing data

CSCvd24066

ASA drops web traffic when IM inspection is enabled.

CSCvd26939

SNMP lists same Hostname for all FTD managed devices

CSCvd29150

Mgmt route deletion removes data plane route too.

CSCvd33044

FTD crash at "cli_xmlserver_thread" while deploying access-control policy

CSCvd33787

Assertion in syslog.c due to uauth

CSCvd36898

FXOS may allocate a CPU core to both control and dataplane which may cause system instability

CSCvd43309

Access-lists not being matched for a newly created object-group

CSCvd46633

timeout conn-holddown shows incorrect syntax help

CSCvd49262

Traceback when trying to save/view access-list with giant object groups (display_hole_og)

CSCvd49550

ASA with 9.5.1 and above does not show SXP socket when managment0/0 is used as src-ip

CSCvd50389

RT#687120: Bookmark Issue with clientless VPN - SAML

CSCvd58417

DCERPC inspection drops packets and breaks communication

CSCvd61308

ASA backup in multicontext fails due to [Running Configurations] ERROR

CSCvd62509

ASA traceback in Thread Name: accept/http when ASDM is displaying "Access Rules"

CSCvd64416

ASA All contexts use the same EIGRP router-ID upon a reload

CSCvd64693

EIGRP routes wrongly being advertising on mgmt routing table vrf after disabling and enabling EIGRP

CSCvd65797

ASA May crash when changing a NAT related object to fqdn

CSCvd66303

Error deploying ASAv on ESXi vCenter 6.5

CSCvd69804

ASA - Interface status change causes VPN traffic disconnect while using ipsec inner-routing-lookup

CSCvd73468

Cluster director connection gets timed out with reason idle timeout

CSCvd76939

ASA policy-map configuration is not replicated to cluster slave

CSCvd77893

ASA may generate an assert traceback while modifying access-group

 

Revision:  Version 9.6(3)1 – 04/03/2017

Files:  asa963-1-smp-k8.bin

Defects resolved since 9.6(3):

 

CSCvd78303

ARP functions fail after 213 days of uptime, drop with error 'punt-rate-limit-exceeded'