Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.10(1)44 – 09/21/2020

Files:  asa9101-44-smp-k8.bin, cisco-asa-fp2k.9.10.1.44.SPA, cisco-asa.9.10.1.44.SPA.csp

Defects resolved since 9.10(1)42:

 

CSCvm77115

Lina Traceback due to invalid TSC values

CSCvn82441

[SXP] Issue with establishing SXP connection between ASA on FPR-2110 and switches

CSCvn93683

ASA: cluster exec show commands not show all output

CSCvn95731

ASA traceback and reload on Thread Name SSH

CSCvp57643

FTD/ASA - Cluster/HA - Master/Active unit does not update all the route changes to Slaves/Standby

CSCvq38889

slib memory manager : mempool mutex vs spinlock selection

CSCvq43920

Cisco Firepower Threat Defense Software Hidden Commands Vulnerability

CSCvr03705

We need to have default route with AD and tunneled at the same time for the same next hub.

CSCvr07460

ASA traceback and reload related to crypto PKI operation

CSCvs56888

Cisco Firepower Threat Defense Software TCP Flood Denial of Service Vulnerability

CSCvt02409

9.12.2.151 snp_cluster_ingress traceback on FPR9300 3-node cluster nested VLAN traffic

CSCvt02409

Cisco Firepower Threat Defense Software Inline Pair/Passive Mode DoS Vulnerability

CSCvt09940

Cisco Firepower 4110 ICMP Flood Denial of Service Vulnerability

CSCvt13445

Cisco ASA and FTD Software FTP Inspection Bypass Vulnerability

CSCvt18028

Cisco ASA and FTD WebVPN CRLF Injection Vulnerability

CSCvt28182

sctp-state-bypass is not getting invoked for inline FTD

CSCvt60190

Cisco ASA and FTD Web Services File Upload Denial of Service Vulnerability

CSCvt70322

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web DoS

CSCvt83121

Cisco Adaptive Security Appliance Software and Firepower Threat Defense OSPFv2 DoS

CSCvu15801

Cisco ASA and FTD Software SIP Denial of Service Vulnerability

CSCvu44910

Cisco ASA Software and FTD Software Web Services Cross-Site Scripting Vulnerability

CSCvu46685

Cisco ASA and FTD Software SSL/TLS Session Denial of Service Vulnerability

CSCvu59817

Cisco Adaptive Security Appliance Software and Firepower Threat Defense SSL VPN DoS

CSCvu75581

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvu75615

Cisco ASA Software and FTD Software WebVPN Portal Access Rule Bypass Vulnerability

CSCvu83309

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvv13835

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvv33712

Cisco ASA Software Web-Based Management Interface Reflected Cross-Site Scripting Vulnerabi

 

 

Revision:  Version 9.10(1)42 – 07/22/2020

Files:  asa9101-42-smp-k8.bin, cisco-asa-fp2k.9.10.1.42.SPA, cisco-asa.9.10.1.42.SPA.csp

Defects resolved since 9.10(1)40:

 

CSCvt03598

Cisco ASA Local File Reading Vulnerability

 

 

Revision:  Version 9.10(1)40 – 05/06/2020

Files:  asa9101-40-smp-k8.bin, cisco-asa-fp2k.9.10.1.40.SPA, cisco-asa.9.10.1.40.SPA.csp

Defects resolved since 9.10(1)37:

 

CSCvt15163

Cisco ASA and FTD Software Web Services Information Disclosure Vulnerability

 

 

Revision:  Version 9.10(1)37 – 02/21/2020

Files:  asa9101-37-smp-k8.bin, cisco-asa-fp2k.9.10.1.37.SPA, cisco-asa.9.10.1.37.SPA.csp

Defects resolved since 9.10(1)32:

 

CSCvo80853

UDP flood causes Lina to run out of memory if blocked

CSCvp49481

Cisco ASA Software and Cisco FTD Software SSL VPN Denial of Service Vulnerability

CSCvp93468

Need to add inactivity timer for aware server sockets

CSCvq70775

FPR2100 FTD Standby unit leaking 9K blocks

 

CSCvq73534

Cisco ASA Software Kerberos Authentication Bypass Vulnerability

 

CSCvr07419

Cisco ASA and FTD Software IPv6 DNS Denial of Service Vulnerability

CSCvr55825

Cisco ASA and FTD Software Path Traversal Vulnerability

CSCvr92327

ASA/FTD may traceback and reload in Thread Name 'PTHREAD-1533'

CSCvs10748

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web DoS

CSCvs50459

Cisco ASA and Cisco FTD Malformed OSPF Packets Processing Denial of Service Vulnerability

 

 

Revision:  Version 9.10(1)32 – 12/17/2019

Files:  asa9101-32-smp-k8.bin, cisco-asa-fp2k.9.10.1.32.SPA, cisco-asa.9.10.1.32.SPA.csp

Defects resolved since 9.10(1)30:

 

CSCvi56715

SNMP polling of FTD on Firepower 2100 Series firewalls shows "octeon" for the "sysName" OID

CSCvr29638

HA FTD on FPR2110 traceback after deploy ACP from FMC

CSCvr35956

Block double-free when combining ServerKeyExchange and ClientKeyExchange fails causes lina traceback

CSCvr85295

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Code Execution Vulnerability

 

 

Revision:  Version 9.10(1)30 – 09/17/2019

Files:  asa9101-30-smp-k8.bin, cisco-asa-fp2k.9.10.1.30.SPA, cisco-asa.9.10.1.30.SPA.csp

Defects resolved since 9.10(1)27:

 

CSCvj98964

ASA may traceback due to SCTP traffic

 

CSCvm40288

Port-Channel issues on HA link

 

CSCvn77388

SDI - SUSPENDED servers cause 15sec delay in the completion of a authentication with a good server

 

CSCvo11280

ASA Enhancement: Generate syslog message once member of the SDI cluster changes state

 

CSCvo14961

ASA may traceback and reload while waiting for "dns_cache_timer" process to finish.

 

CSCvo28118

Traceback in VPN Clustering HA timer thread when member tries to join the cluster

 

CSCvo43795

OSPF Process ID doesnot change even after clearing OSPF process

 

CSCvo73250

ENH: ACE details for warning "found duplicate element"

 

CSCvo74397

ENH: Add process information to "Command Ignored, configuration in progress..."

 

CSCvo83169

Cisco ASA Software and FTD Software FTP Inspection Denial of Service Vulnerability

 

CSCvo86038

Simultaneous FINs on flow-offloaded flows lead to stale conns

 

CSCvo90998

LACPDUs should not be sent to snort for inline-set interfaces

 

CSCvp04186

cts import-pac tftp: syntax does not work

 

CSCvp12582

Option to display port number on access-list instead of well known port name on ASA

 

CSCvp19910

Unable to process gtpv1 identification req message for header TEID : 0

 

CSCvp19998

ASA drops GTPV1 SGSN Context Req message with header TEID:0

 

CSCvp33341

Cisco ASA and Firepower Threat Defense Software WebVPN Cross-Site Scripting Vulnerability

 

CSCvp49576

FTD Cluster traceback experienced when other unit leaves the Cluster

 

CSCvp55901

LINA traceback on ASA in HA Active Unit repeatedly

 

CSCvp66559

Deploy fails on FTD HA due to exception when parsing big xml response

 

CSCvp76944

Cisco ASA and FTD Software WebVPN CPU Denial of Service Vulnerability

 

CSCvp84546

ASA 9.9.2 Clientless WebVPN - HTML entities are incorrectly decoded when processing HTML

CSCvp91296

Firepower 4100 connection counts mismatch between active and standby ASA

CSCvq01459

LINA Traceback after upgrade to 9.12.2.1

CSCvq05113

ASA failover LANTEST messages are sent on first 10 interfaces in the configuration.

CSCvq11513

Traceback: "saml identity-provider" command will crash multi-context ASAs

CSCvq12411

ASA may traceback due to SCTP traffic despite fix CSCvj98964

CSCvq13442

When deleting context the ssh key-exchange goes to Default GLOBALLY!

CSCvq17263

FTD LINA traceback at DATAPATH-8-15821

CSCvq21607

ssl trust-point command will be removed when restoring backup via CLI

CSCvq24134

ASA IKEv2 - ASA sends additional delete message after initiating a phase 2 rekey

CSCvq25626

Watchdog on ASAv when logging to buffer

CSCvq26794

GTP response messages with non existent cause are getting dropped with error message TID is 0

CSCvq27010

Memory leak observed when ASA-SFR dataplane communication flaps

CSCvq28250

ENH: ASA Cluster debug for syn cookie issues

CSCvq39317

ASA  is unable to verify the file integrity

CSCvq44665

FTD/ASA : Traceback in Datapath with assert snp_tcp_intercept_assert_disabled

CSCvq54667

SSL VPN may not be able to establish due to SSL negotiation issue

CSCvq60131

ASA traceback observed when moving EZVPN spokes to the device.

CSCvq63024

Dual stacked ASAv manual failover issues

CSCvq64742

ASA5515-K9 standby traceback in Thread Name ssh

CSCvq65241

ASA Traceback on Saleen in Thread Name: IPv6 IDB

CSCvq69111

Traceback: Cluster unit lina assertion in thread name:Cluster controller

CSCvq70468

ASA cluster does not flush OSPF routes

CSCvq75743

ASA:BGP recursive route lookup for destination 3 hop away  is failing.

CSCvq77547

Connections fail to replicate in failover due to failover descriptor mis-match on port-channels

CSCvq78828

Cisco Firepower Threat Defense Software Generic Routing Encapsulation Tunnel IPv6 DoS

CSCvq80318

ASA generates incorrect error message about PCI cfg space when enumerating Internal-Data0/1

CSCvq80735

Cannot add neighbor in BGP when the neighbor is on the same subnet as one interface

CSCvq91645

Flow Offload Hashing Change of Behavior

 

 

Revision:  Version 9.10(1)27 – 07/24/2019

Files:  asa9101-27-smp-k8.bin, cisco-asa-fp2k.9.10.1.27.SPA, cisco-asa.9.10.1.27.SPA.csp

Defects resolved since 9.10(1)22:

 

CSCvh13869

ASA IKEv2 unable to open aaa session: session limit [2048] reached

 

CSCvj61580

ASA traceback with Thread: DATAPATH-8-2035

 

CSCvk22322

ASA Traceback (watchdog timeout) when syncing config from active unit (inc. cachefs_umount)

 

CSCvk29685

Traceback in DATAPATH on ASA

 

CSCvm64400

IKEv2: IKEv2-PROTO-2: Failed to allocate PSH from platform

 

CSCvm81129

Invalid RA VPN session's assigned IPv6 address in ADI sessions are received in FTD

 

CSCvm85823

Not able to ssh, ssh_exec: open(pager) error on console

 

CSCvn86777

Deployment on FTD with low memory results on interface nameif to be removed

 

CSCvo41572

FMC shows connection events with packet count as 0

 

CSCvo45755

ASA SCP transfer to box stall mid-transfer

 

CSCvo47390

ASA traceback in thread SSH

 

CSCvo65741

ASA: BGP routes is cleared on routing table after failover occur and bgp routes are changed

 

CSCvo67421

easyVPN got broke on lina_dev [201.4.1.106]

 

CSCvo68184

management-only of diagnostic I/F on secondary FTD get disappeared

 

CSCvo87985

ASA sends password in plain text for "copy" command

 

CSCvo88762

FTD inline/transparent sends packets back through the ingress interface

 

CSCvo97979

The delay command in interface configuration is modified after rebooted

 

CSCvp04134

Traceback in HTTP CLI Exec when upgrading to 9.12.1

 

CSCvp10132

AnyConnect connections fail with TCP connection limit exceeded error

 

CSCvp14674

ASAv Azure: Route table BGP propagation setting reset when ASAv fails over

 

CSCvp16482

ASA reloads when establishing simultaneous ASDM sessions

 

CSCvp16536

ASA traceback and reload observed in Datapath due to SIP inspection.

 

CSCvp16945

Cisco ASA Software and FTD Software MGCP Denial of Service Vulnerabilities

CSCvp16949

Cisco ASA Software and FTD Software MGCP Denial of Service Vulnerabilities

CSCvp19549

FTD lina cored with Thread name: cli_xml_server

 

CSCvp24728

Random SGT tags added by FTD

 

CSCvp29692

FIPS mode gets disabled after rollback from a failed policy deploy

 

CSCvp35141

ASA sends invalid redirect response for POST request

 

CSCvp35384

IKEv2 RA Generic client - stuck outgoing asp table entry - traffic encrypted with stale SPI

 

CSCvp43066

DHCP NACK silently dropped by ASA sent from DHCP server if configured as DHCP relay

 

CSCvp45882

Cisco ASA Software and FTD Software SIP Inspection Denial of Service Vulnerability

 

CSCvp49790

Cisco ASA Software and FTD Software OSPF LSA Processing Denial of Service Vulnerability

 

CSCvp55880

Fail-Closed FTD passes packets through on Snort processes down

 

CSCvp59864

IP Address stuck in local pool and showing as "In Use" even when the AnyConnect client disconnects

 

CSCvp63068

Thread Name: CP DP SFR Event Processing traceback

 

CSCvp67392

ASA/FTD HA Data Interface Heartbeat dropped due to Reverse Path Check

 

CSCvp70699

ASA Failover split brain (both units active) after rebooting a Firepower chassis

 

CSCvp71180

MCA+AAA+OTP with RADIUS challenge fails to send aggauth handle in challenge

 

CSCvp72412

Time zone in syslogs  messages

 

CSCvp80775

Unsupported runtime JavaScript exception handling in the client side WebVPN rewriter

 

CSCvp97916

Executing 'failover' twice on active unit, clears interface configuration on standby unit

 

CSCvq12070

Not able to establish more than 2 simultaneous ASDM sessions

 

 

 

Revision:  Version 9.10(1)22 – 05/10/2019

Files:  asa9101-22-smp-k8.bin, cisco-asa-fp2k.9.10.1.22.SPA, cisco-asa.9.10.1.22.SPA.csp

Defects resolved since 9.10(1)17:

 

CSCvf83160

Traceback on Thread Name: DATAPATH-2-1785

CSCvi47523

SSP-NTP: ssp-ntp script monitoring script enhancements for XRU, KP

CSCvm27111

FTD Lina traceback while removing OSPF configuration.

CSCvm36362

Route tracking failure

CSCvm50421

ASA traceback on slave/standby during sync config due to OSPF/EIGRP and IPv6 used together in ACE

CSCvm70274

tcp proxy: ASA traceback on DATAPATH

CSCvn25970

Traceback in Firepower 4120

CSCvn46358

overloading of the lina msglyr infra due to the sending of VPN status messages

CSCvn66248

Configuring "boot config" has no effect if file was modified off-box and copied back on

CSCvn76875

Graceful Restart BGP does not work intermittently

CSCvo03700

ASA may traceback in thread logger when cluster is enabled on slave unit

CSCvo12057

DHCPRelay does not consume DHCP Offer packet with Unicast flag

CSCvo17775

EIGRP breaks when new sub-interface is added and "mac-address auto" is enabled

CSCvo31695

Traceback in threadname DATAPATH-0-1668 while freeing memory block

CSCvo38051

segfault in ctm_ipsec_pfkey_parse_msg at ctm_ipsec_pfkey.c:602

CSCvo43679

FTD Lina traceback, due to packet looping in the system by normaliser

CSCvo47562

VPN sessions failing due to PKI handles not freed during rekeys

CSCvo48838

Lina does not properly report the error for configuration line that is too long

CSCvo51265

Cisco Adaptive Security Appliance Software Secure Copy Denial of Service Vulnerability

CSCvo58847

Enhancement to address high IKE CPU seen due to tunnel replace scenario

CSCvo60580

ASA traceback and reloads when issuing "show inventory" command

CSCvo62031

ASA Traceback and reload while running IKE Debug

CSCvo62077

Cisco Firepower Threat Defense Software VPN System Logging Denial of Service Vulnerability

CSCvo66534

Traceback and reload citing Datapath as affected thread

CSCvo66920

Enhancement: add counter for Duplicate remote proxy

CSCvo72462

Do not decrypt rule causes traffic interruptions.

CSCvo74350

ASA may traceback and reload. Potentially related to WebVPN traffic

CSCvo80501

Standby Firewall reloads with a traceback upon doing a manual failover

CSCvo87930

HTTP with ipv6 using w3m is failing

CSCvo90153

ASA unable to authenticate users with special characters via https

CSCvo93872

Memory leak while inspecting GTP traffic

CSCvp07143

DTLS 1.2 and AnyConnect oMTU

CSCvp12052

ASA may traceback and reload. suspecting webvpn related

CSCvp18878

ASA: Watchdog traceback in Datapath

CSCvp32617

established tcp does not work post 9.6.2

CSCvp36425

ASA 5506/5508/5516 traceback in Thread Name octnic_hm_thread

 

 

Revision:  Version 9.10(1)17 – 04/08/2019

Files:  asa9101-17-smp-k8.bin, cisco-asa-fp2k.9.10.1.17.SPA, cisco-asa.9.10.1.17.SPA.csp

Defects resolved since 9.10(1)11:

 

CSCuz22961

Support for more than 255 characters for Split DNS value

CSCvj01704

ASA is getting traceback with reboot only on Spyker aftr shutdown SFR module

CSCvj06993

ASA HA with NSF: NSF is not triggered properly when there is an Interface failure  in ASA HA

CSCvj82652

Deployment changes are not pushed to the device due to disk0 mounted on read-only

CSCvm00066

ASA is stuck on "reading from flash"  for several hours

CSCvm16724

FXOS ASA/FTD needs means to poll Internal-data interface counters

CSCvn17347

Traceback and reload when displaying CPU profiling results

CSCvn25949

Digitial Signature Verification Failed during upload of Rest-Api image to ASA

CSCvn30108

The 'show memory' CLI output is incorrect on ASAv

CSCvn31347

ACL Unable to configure an ACL after access-group configuration error

CSCvn38453

ASA: Not able to load Quovadis Root Certificate as trustpoint when FIPS is enabled

CSCvn67137

ASA5506 may slowly leak memory when using NetFlow

CSCvn68527

KP:AnyConnect used IP from pool shows as available

CSCvn72650

FTD Address not mapped traceback on 6.3.0.x release

CSCvn75368

FPR platform IPsec VPN goes down intermittently

CSCvn78593

Control-plane ACL doesn't work correctly on FTD

CSCvn78870

ASA Multicontext traceback and reload due to allocate-interface out of range command

CSCvn95711

Traceback on Thread Name: Unicorn Admin Handler after adding protocol to IKEV2 ipsec-proposal

CSCvn96898

Memory Leak in DMA_Pool in binsize 1024 with SCP download

CSCvo02097

Upgrading ASA cluster to 9.10.1.7 cause traceback

CSCvo03808

Deploy from FMC fails due to OOM with no indication of why

CSCvo04444

Ikev2 tunnel creation fails

CSCvo06216

Support more than 255 chars for Split DNS-commit issue in hanover for CSCuz22961

CSCvo09046

Upgrading ASA cluster to 9.10.1.7 cause low memory

CSCvo11077

Cisco ASA Software and FTD Software IKEv1 Denial of Service Vulnerability

CSCvo13497

Unable to remove access-list with 'log default' keyword

CSCvo19247

Traceback while processing an outbound SSL packet

CSCvo21210

PDTS has incorrect numa node info resulting in incorrect load balancing

CSCvo23222

AnyConnect session rejected due to resource issue in multi context deployments

CSCvo27109

Standby may enter reboot loop upon upgrading to 9.6(4)20 from 9.6(4)6

CSCvo42174

ASA IPSec VPN EAP Fails to Load Valid Certificate in PKI

CSCvo55151

crypto ipsec inner-routing-lookup should not be allowed to be configured with VTI present

CSCvo56675

ASA traceback and reload when trying to switch from ACTIVE to STANDBY. Thread Name: fover_FSM_thread

CSCvo63240

Smart Tunnel bookmarks don't work after upgrade giving certificate error

 

 

Revision:  Version 9.10(1)11 – 02/25/2019

Files:  asa9101-11-smp-k8.bin, cisco-asa-fp2k.9.10.1.11.SPA, cisco-asa.9.10.1.11.SPA.csp

Defects resolved since 9.10(1)10:

 

CSCvn66153

ENH:  Add Syslog Support for DCD

 

 

Revision:  Version 9.10(1)10 – 02/19/2019

Files:  asa9101-10-smp-k8.bin, cisco-asa-fp2k.9.10.1.10.SPA, cisco-asa.9.10.1.10.SPA.csp

Defects resolved since 9.10(1)7:

 

CSCvi71622

Traceback in DATAPATH on standby FTD

 

CSCvj00363

ASA may traceback and reload with combination of packet-tracer and captures

 

CSCvj01704

ASA is getting traceback with reboot only on Spyker aftr shutdown SFR module

 

CSCvj34599

Cisco Adaptive Security Appliance Software Cross-site Request Forgery Vulnerability

 

CSCvk18330

Active FTP Data transfers fail with FTP inspection and NAT

CSCvk29263

SSH session stuck after committing changes within a Configure Session.

CSCvk72958

Qos applied on interfaces doesn't work.

CSCvm08769

Standby unit sending BFD packets with active unit IP, causing BGP neighborship to fail.

CSCvm80779

ASA not inspecting H323 H225

CSCvm82290

ASA core blocks depleted when host unreachable in IRB configuration

CSCvn09367

Prevent administrators from installing CXSC module on ASA 5500-X

CSCvn09612

ASA/FTD Connection Idle Timers Not Increasing For Inactive Offloaded Sessions

CSCvn22833

ADI process fails to start on ASA on Firepower 4100

CSCvn23254

SNMPv2 pulls empty ifHCInOctets value if Nameif is configured on the interface

CSCvn30393

ASA Traceback in emweb/https during Anyconnect Auth/DAP assessment

CSCvn32657

ASA traceback when removing interface configuration used in call-home

CSCvn44201

ASA discards OSPF hello packets with LLS TLVs sent from a neighbor running on IOS XE 16.5.1 or later

CSCvn47599

RA VPN + SAML authentication causes 2 authorization requests against the RADIUS server

CSCvn47800

ASA stops authenticating new AnyConnect connections due to fiber exhaustion

CSCvn55007

DTLS fails after rekey

CSCvn56095

selective acking not happening with SSL crypto hardware offload

CSCvn61662

ASA 5500-X may reload without crashinfo written due to CXSC module continuously reloading

CSCvn62787

To support multiple retry on devcmd failure to CRUZ during flow table configuration update.

CSCvn64418

ISA300 interop issue with Nokia 7705 router

CSCvn69213

ASA traceback and reload due to multiple threads waiting for the same lock - watchdog

CSCvn73962

ASA 5585 9.8.3.14 traceback in Datapath with ipsec

CSCvn76829

ASA as an SSL Client Memory Leak in Handshake Error path

CSCvn77636

ASA/webvpn: FF and Chrome: Bookmark is not rendered with Grammar Based Parser

CSCvn94100

Process Name: lina | ASA traceback caused by Netflow

CSCvn97591

Packet Tracer fails with "ERROR: TRACER: NP failed tracing packet", with circular asp drop captures

 

 

Revision:  Version 9.10(1)7 – 12/19/2018

Files:  asa9101-7-smp-k8.bin, cisco-asa-fp2k.9.10.1.7.SPA, cisco-asa.9.10.1.7.SPA.csp

Defects resolved since 9.10(1)2:

 

CSCvg40735

GTP inspection may spike cpu usage

CSCvh14743

IKEv2 MOBIKE session with Strongswan/3rd party client fails due to DPD with NAT detection payload.

CSCvi77643

Hanging downloads and slow downloads on a FPR4120 due to http inspect

CSCvj01704

ASA is getting traceback with reboot only on Spyker aftr shutdown SFR module

CSCvj58342

Multicast dropped after deleting a security context

CSCvj97213

ASA IKEv2 capture type isakmp is saving corrupted packets or is missing packets

CSCvk14537

SSH/Telnet Management sessions may get stuck in pc ftpc_suspend

CSCvk18330

Active FTP Data transfers fail with FTP inspection and NAT

CSCvk30775

ENH: Addition of 'show fragment' to 'show tech' output

CSCvk30779

ENH: Addition of 'show ipv6 interface' to 'show tech' output

CSCvk30783

ENH: Addition of 'show aaa-server' to 'show tech' output

CSCvk31035

KVM (FTD): Mapping web server through outside not working consistent with other platforms

CSCvk51181

FTD IPV6 traffic outage after interface edit and deployment part 1/2

CSCvk62896

ASA IKEv2 traceback while deleting SAs

CSCvk66771

The CPU profiler stops running without having hit the threshold and without collecting any samples.

CSCvm17985

Initiating write net command with management access for BVI interfaces does not succeed

CSCvm24706

GTP delete bearer request is being dropped

CSCvm49283

Make Object Group Search Threshold disabled by default, and configurable. Causes outages.

CSCvm53531

PIX-ASA rest-api unauthorized access.

 

CSCvm55091

HA failed primary unit shows active while "No Switchover" status on FP platforms

CSCvm56371

ASA wrongly removes dACL for all Anyconnect clients which has the same dACL attached

CSCvm56719

Traceback high availability standby unit Thread Name: vpnfol_thread_msg

CSCvm65725

ASA kerberos auth fails switch to TCP if server has response too big (ERR_RESPONSE_TOO_BIG)

CSCvm67273

ASA: Memory leak due to PC alloc_fo_ipsec_info_buffer_ver_1+136

CSCvm67316

ASA: Add additional IKEv2/IPSec debugging for CSCvm70848

CSCvm70848

ASA: IPSec SA installation failure due to 'Failed to create session mgmt entry for SPI <>'

CSCvm72378

ASA: CLI: User should not be allowed to create network object "ANY"

CSCvm78449

Unable to modify access control license entry with log default command

CSCvm82930

FTD: SSH to ASA Data interface fails if overlapping NAT statement is configured

CSCvm88004

SSH Service on ASA echoes back each typed/pasted character in its own packet

CSCvm92359

Blocks exhaustion snapshot was not captured on ASA

CSCvn03966

FTD - When "object-group-search" is pushed through flexconfig, all ACLs get deleted causing outage.

CSCvn09322

FTD device rebooted after taking Active State for less than 5 minutes

CSCvn09640

FTD: Need ability to trust ethertype ACLs from the parser. Need to allow BPDU to pass through

CSCvn15757

ASA may traceback due to SCTP traffic inspection without NULL check

CSCvn19823

ASA : Failed SSL connection not getting deleted and depleting DMA memory

CSCvn32657

ASA traceback when removing interface configuration used in call-home

CSCvn33943

Standby node traceback in wccp_int_statechange() with HA configuration sync

CSCvn37829

ASA should allow GCM(SSL) connections to use DMA_ALT1 when primary DMA pool is exhausted

 

 

Revision:  Version 9.10(1)2 – 11/08/2018

Files:  asa9101-2-smp-k8.bin, cisco-asa-fp2k.9.10.1.2.SPA, cisco-asa.9.10.1.2.SPA.csp

Defects resolved since 9.10(1):

 

CSCvm43975

Cisco Adaptive Security Appliance Software and FTD Software Denial of Service Vulnerability