Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Caution: If you are using CSM, and you upgrade to ASA Version 9.8(3)26 or later, then you must upgrade CSM to Version 4.19 or later. Earlier versions of CSM are not compatible.

 

Note: ASA 9.8(4)45 and later requires ASDM 7.18(1)152 or later. The ASA now validates whether the ASDM image is a Cisco digitally signed image. If you try to run an older ASDM image than 7.18(1.152) with an ASA version with this fix, ASDM will be blocked and the message “%ERROR: Signature not valid for file disk0:/<filename>” will be displayed at the ASA CLI. (CSCwb05291, CSCwb05264)

 

Revision:  Version 9.8(4)48 – 02/14/2023

Files:  asa984-48-smp-k8.bin, cisco-asa-fp2k.9.8.4.48.SPA, cisco-asa-fp1k.9.8.4.48.SPA, cisco-asa.9.8.4.48.SPA.csp

Defects resolved since 9.8(4)46

 

 

CSCwa04262

Cisco ASA Software SSL VPN Client-Side Request Smuggling Vulnerability via "/"URI

CSCwd95043

Cisco ASA and FTD VPN Web Client Services Client-Side Request Smuggling Vulnerability via "/+CSCOE+/"URI

 

Cisco ASA Software SSL VPN Client-Side Request Smuggling Vulnerability via "/"URI

 

Revision:  Version 9.8(4)46 – 11/09/2022

Files:  asa984-46-smp-k8.bin, cisco-asa-fp2k.9.8.4.46.SPA, cisco-asa-fp1k.9.8.4.46.SPA, cisco-asa.9.8.4.46.SPA.csp

Defects resolved since 9.8(4)45

 

CSCwa81795

Cisco ASA and FTD Software VPN Authorization Bypass Vulnerability

CSCwb52401

Cisco Firepower Threat Defense Software Privilege Escalation Vulnerability

CSCwb87950

Cisco ASA Software and FTD Software Web Services Interface Denial of Service Vulnerability

CSCwb93914

Cisco ASA Software and FTD Software Web Services Interface Denial of Service Vulnerability

CSCwb63827

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DoS

 

Revision:  Version 9.8(4)45 – 08/30/2022

Files:  asa984-45-smp-k8.bin, cisco-asa-fp2k.9.8.4.45.SPA, cisco-asa-fp1k.9.8.4.45.SPA, cisco-asa.9.8.4.45.SPA.csp

Defects resolved since 9.8(4)44

 

CSCwb05291

Cisco ASDM and ASA Software Client-side Arbitrary Code Execution Vulnerability

 

 

Revision:  Version 9.8(4)44 – 06/08/2022

Files:  asa984-44-smp-k8.bin, cisco-asa-fp2k.9.8.4.44.SPA, cisco-asa-fp1k.9.8.4.44.SPA, cisco-asa.9.8.4.44.SPA.csp

Defects resolved since 9.8(4)43

 

CSCvz09106

Cisco ASA and FTD Software SSL VPN Denial of Service Vulnerability

CSCvz70595

Cisco ASA Software and FTD Software Web Services Interface Denial of Service Vulnerability

CSCvz76966

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DNS DoS

CSCvz89545

SSL VPN performance degraded and significant stability issues after upgrade

CSCwa14485

Cisco Firepower Threat Defense Software Denial of Service Vulnerability

CSCwa47041

Watchdog Traceback in Thread Name: aaa_shim_thread

CSCwa33898

Cisco Adaptive Security Appliance Software Clientless SSL VPN Heap Overflow Vulnerability

 

 

Revision:  Version 9.8(4)43 – 03/23/2022

Files:  asa984-43-smp-k8.bin, cisco-asa-fp2k.9.8.4.43.SPA, cisco-asa-fp1k.9.8.4.43.SPA, cisco-asa.9.8.4.43.SPA.csp

Defects resolved since 9.8(4)41:

 

CSCvw51985

ASA: AnyConnect sessions cannot be resumed due to ipv6 DACL failure

CSCvw97821

ASA: VPN traffic does not pass if no DACL is provided in CoA

CSCvw98840

ASA: DACL with no IPv6 entries is not applied to v6 traffic after CoA

CSCvz64470

ASA/FTD Traceback and reload due to memory corruption when generating ICMP unreachable message

CSCvz92016

ASA Privilege Escalation with valid user in AD

CSCwa65389

ASA traceback and reload in Unicorn Admin Handler when change interface configuration via ASDM

 

 

Revision:  Version 9.8(4)41 – 10/13/2021

Files:  asa984-41-smp-k8.bin, cisco-asa-fp2k.9.8.4.41.SPA, cisco-asa-fp1k.9.8.4.41.SPA, cisco-asa.9.8.4.41.SPA.csp

Defects resolved since 9.8(4)40:

 

CSCvu08773

R291: Blade reboots continuously on doing backward compatibility testing with 9.8.4

 

 

Revision:  Version 9.8(4)40 – 09/15/2021

Files:  asa984-40-smp-k8.bin, cisco-asa-fp2k.9.8.4.40.SPA, cisco-asa-fp1k.9.8.4.40.SPA, cisco-asa.9.8.4.40.SPA.csp

Defects resolved since 9.8(4)39:

 

CSCvx11295

ASA may traceback and reload on thread Crypto CA

CSCvx94398

Secondary ASA could not get the startup configuration

CSCvy64492

ASAv adding non-identity L2 entries for own addresses on MAC table and dropping HA hellos

 

 

Revision:  Version 9.8(4)39 – 06/08/2021

Files:  asa984-39-smp-k8.bin, cisco-asa-fp2k.9.8.4.39.SPA, cisco-asa-fp1k.9.8.4.39.SPA, cisco-asa.9.8.4.39.SPA.csp

Defects resolved since 9.8(4)35:

 

CSCvp69936

ASA Traceback on tcp_intercept Thread name: Threat detection

CSCvw03628

ASA will not import CA certificate with name constraint of RFC822 Name set as empty

CSCvx73164

Lasso SAML Implementation Vulnerability Affecting Cisco Products: June 2021

 

 

Revision:  Version 9.8(4)35 – 04/28/2021

Files:  asa984-35-smp-k8.bin, cisco-asa-fp2k.9.8.4.35.SPA, cisco-asa-fp1k.9.8.4.35.SPA, cisco-asa.9.8.4.35.SPA.csp

Defects resolved since 9.8(4)34:

 

CSCvv65184

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web DoS

CSCvw06298

ASA duplicate MAC addresses in Shared Interfaces of different Contexts causing traffic impact

 

 

Revision:  Version 9.8(4)34 – 03/23/2021

Files:  asa984-34-smp-k8.bin, cisco-asa-fp2k.9.8.4.34.SPA, cisco-asa-fp1k.9.8.4.34.SPA, cisco-asa.9.8.4.34.SPA.csp

Defects resolved since 9.8(4)33:

 

CSCvv16082

stress/low memory: assert: mh->mh_mem_pool > MEMPOOL_UNDEFINED && mh->mh_mem_pool < MEMPOOL_MAX_TYPE

CSCvv56644

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web DoS

CSCvw12100

ASA stale VPN Context seen for site to site and AnyConnect sessions

CSCvw26544

Cisco ASA and FTD Software SIP Denial of Service Vulnerability

CSCvw52609

Cisco ASA and FTD Software Web Services Buffer Overflow Denial of Service Vulnerability

CSCvw53796

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerability

CSCvw87788

ASA traceback and reload webvpn thread

CSCvw95301

ASA traceback and reload with Thread name: ssh when capture was removed

CSCvx27430

ASA: Unable to import PAC file if FIPS is enabled.

 

 

Revision:  Version 9.8(4)33 – 02/24/2021

Files:  asa984-33-lfbff-k8.SPA, asa984-33-smp-k8.bin

Defects resolved since 9.8(4)32:

 

CSCvw53884

M500IT Model Solid State Drives on ASA5506 may go unresponsive after 3.2 Years in service

CSCvx09123

M500IT Model Solid State Drives on ISA3000 may go unresponsive after 3.2 Years in service

 

 

Revision:  Version 9.8(4)32 – 11/17/2020

Files:  asa984-32-smp-k8.bin, cisco-asa-fp2k.9.8.4.32.SPA, cisco-asa-fp1k.9.8.4.32.SPA, cisco-asa.9.8.4.32.SPA.csp

Defects resolved since 9.8(4)29:

 

CSCvj29479

Traceback in cluster_route_status_callback while disabling/enabling cluster back-to-back

CSCvo34210

ASA running 9.6.4.20 Traceback in threadname Unicorn Proxy Thread

CSCvt71529

ASA traceback and reload during SSL handshake

CSCvt75760

Traceback/Page-fault in Clientless WebVPN due to HTTP cleanup

CSCvu66332

Lina traceback when FTD is configured with passive interface in HA with span traffic on it.

CSCvu89110

ASA: Block new conns even when the "logging permit-hostdown" is set & TCP syslog is down

CSCvv15572

ASA traceback observed when "config-url" is entered while creating new context

CSCvv49800

6.6.1-71: HA switchover doesn't happen with graceful reboot of QP chassis

CSCvv58332

ASA/FTD is reading BGP MP_REACH_NLRI attribute's next-hop bytes in reverse order

CSCvv66005

ASA traceback and reload on inspect esmtp

CSCvv69258

access-list: FP9300 9.8.4.10ASA missing entries in the object expand after object-group modification

CSCvv73017

Traceback due to fover and ssh thread

CSCvv86926

Unexpected traceback and reload on FTD creating a Core file

CSCvv88017

ASA: EasyVPN HW Client triggers duplicate phase 2 rekey causing disconnections across the tunnel

CSCvv90720

Mac address-table is flapping on 3850 when ASA etherchannel is configued with active mode

CSCvw05393

Certificate validation syslog is not generated on OCSP revocation check

CSCvw06195

ASA traceback cp_midpath_process_thread

CSCvw12008

ASA traceback and reload while executing "show tech-support" command

CSCvw26171

ASA syslog traceback while strncpy NULL string passed from SSL library

CSCvw27301

IKEv2 with EAP, MOBIKE status fails to be processed.

 

 

Revision:  Version 9.8(4)29 – 10/07/2020

Files:  asa984-29-smp-k8.bin, cisco-asa-fp2k.9.8.4.29.SPA, cisco-asa-fp1k.9.8.4.29.SPA, cisco-asa.9.8.4.29.SPA.csp

Defects resolved since 9.8(4)26:

 

CSCvo31790

Cisco Firepower Threat Defense Software Management Interface DoS Vulnerability

CSCvq47743

AnyConnect and Management Sessions fail to connect after several weeks

CSCvr35872

ASA traceback Thread Name: DATAPATH-0-1388 PBR 9.10(1)22

CSCvu06767

Lina cores on multi-instance causing a boot loop on both logical-devices

CSCvu16423

ASA 9.12(2) - Multiple tracebacks due to Unicorn Proxy Thread

CSCvu29660

Block exhaustion snapshot not created when available blocks goes to zero

CSCvu33992

traceback: ASA reloaded lina_sigcrash+1394

CSCvu45748

ASA traceback in threadname 'ppp_timer_thread'

CSCvu45822

ASA experienced a traceback and reloaded

CSCvu59817

Cisco Adaptive Security Appliance Software and Firepower Threat Defense SSL VPN DoS

CSCvu70931

Cluster / aaa-server key missing after "no key config-key" is entered

CSCvv04584

Multicast traffic is being dropped with the resson no-mcast-intrf

CSCvv08684

Cluster site-specific MAC addresses not rewritten by flow-offload

CSCvv10778

Traceback and reload in thread DATAPATH-1-1320 after upgrade

CSCvv12857

ASA gets frozen after crypto engine failure

CSCvv13835

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvv23370

Observed traceback in FPR2130 while running webVPN, SNMP related traffic.

CSCvv25394

After upgrade ASA swapped names for disks, disk0 became disk1 and vice versa.

CSCvv28997

ASA Traceback and reload on thread name Crypto CA

CSCvv31334

Lina traceback and reload seen on trying to switch peer on KP HA with 6.6.1-63

CSCvv32425

ASA traceback when running show asp table classify domain permit

CSCvv33712

Cisco ASA Software Web-Based Management Interface Reflected Cross-Site Scripting Vulnerability

CSCvv34003

snmpwalk for OID 1.3.6.1.2.1.47.1.1.1.1.5 on ISA 3000 returning value of 0 for .16 and .17

CSCvv34140

ASA IKEv2 VTI - Failed to request SPI from CTM as responder

CSCvv40223

Error parsing flash:/LOCAL-CA-SERVER/LOCAL-CA-SERVER.cdb, when trying to modify/read the user-db

CSCvv41453

Removing static ipv6 route from management-only route table affects data traffic

CSCvv43484

ASA stops processing RIP packets after system upgrade

CSCvv44270

ASAv5 reloads without traceback.

CSCvv49698

ASA Anyconnect url-redirect not working for ipv6

CSCvv50338

Traceback Cluster unit on snpi_nat_xlate_destroy+2508

CSCvv53696

ASA/FTD traceback and reload during AAA or CoA task of Anyconnect user

CSCvv57842

WebSSL clientless user accounts being locked out on 1st bad password

CSCvv58605

ASA traceback and reload in thread:Crypto CA,mem corruption by unvirtualized pki global table in MTX

CSCvv62305

ASA traceback and reload in fover_parse when attempting to join the failover pair.

CSCvv63412

ASA dropping all traffic with reason "No route to host" when tmatch compilation is ongoing

 

 

Revision:  Version 9.8(4)26 – 08/27/2020

Files:  asa984-26-smp-k8.bin, cisco-asa-fp2k.9.8.4.26.SPA, cisco-asa-fp1k.9.8.4.26.SPA, cisco-asa.9.8.4.26.SPA.csp

Defects resolved since 9.8(4)25:

 

CSCvf88062

CTM: Nitrox S/G lengths need to be validated

CSCvh19161

ASA/FTD traceback and reload in Thread Name: SXP CORE

CSCvk51778

show inventory (or) "show environment" on ASA 5515/5525/5545/5555 shows up Driver/ioctl error logs

CSCvn82441

[SXP] Issue with establishing SXP connection between ASA on FPR-2110 and switches

CSCvq43920

Cisco Firepower Threat Defense Software Hidden Commands Vulnerability

CSCvq87625

ENH: Addition of 'show run all sysopt' to 'show tech' output

CSCvr60195

ASA/FTD may traceback and reload in Thread Name 'HTTP Cli Exec'

CSCvr68872

Secondary unit exceed platform context count limit in split brain scenario when failover link down

CSCvr98924

ASA traceback and reload due to routing subsystem

CSCvr99642

ASA traceback and reload multiple times with trace "webvpn_periodic_signal"

CSCvs56888

Cisco Firepower Threat Defense Software TCP Flood Denial of Service Vulnerability

CSCvt13445

Cisco ASA and FTD Software FTP Inspection Bypass Vulnerability

CSCvt50528

Warning Message for default settings with Installation of Certificates in ASA/FTD - CLI

CSCvt53640

ASA5585 traceback and reload after upgrading SFR from 6.4.0 to 6.4.0.9-34

CSCvt91521

Crypto accelerator bias setting should be included in show tech

CSCvu15801

Cisco ASA and FTD Software SIP Denial of Service Vulnerability

CSCvu29395

Traceback observed while performing master role change with active IGMP joins

CSCvu46685

Cisco ASA and FTD Software SSL/TLS Session Denial of Service Vulnerability

CSCvu47925

Cisco ASA and FTD IP Fragment Memory Leak Vulnerability

CSCvu48285

ASA configured with TACACS REST API: /cli api fail with "Command authorization failed" message

CSCvu55843

ASA traceback after TACACS authorized user made configuration changes

CSCvu61704

ASA high CPU with intel_82576_check_link_thread impacting on overall unit performance

CSCvu72094

ASA traceback and reload on thread name DATAPATH

CSCvu72658

AnyConnect Connected Client IPs Not Advertised into OSPF Intermittently

CSCvu73207

DSCP values not preserved in DTLS packets towards AnyConnect users

CSCvu75581

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvu75615

Cisco ASA Software and FTD Software WebVPN Portal Access Rule Bypass Vulnerability

CSCvu77095

ASA unable to delete ACEs with remarks and display error "Specified remark does not exist"

CSCvu83178

EIGRP summary route not being replicated to standby and causing outage after switchover

CSCvu83309

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvu90727

Native VPN client with EAP-TLS authentication fails to connect to ASA

CSCvu91792

SNMP IfDiscards OIDs for Internal-Data 0/0 and 0/1 wrong Values

CSCvv07864

Multicast EIGRP traffic not seen on internal FTD interface

CSCvv09944

Lina Traceback during FTD deployment when WCCP config is being pushed

 

 

Revision:  Version 9.8(4)25 – 07/08/2020

Files:  asa984-25-smp-k8.bin, cisco-asa-fp2k.9.8.4.25.SPA, cisco-asa-fp1k.9.8.4.25.SPA, cisco-asa.9.8.4.25.SPA.csp

Defects resolved since 9.8(4)22:

 

CSCve39879

ASA Will Not Establish L2L With "Detected unsupported failover version" Messages

CSCvn95731

ASA traceback and reload on Thread Name SSH

CSCvq46587

After failover, Active unit tcp sessions are not removed when timeout reached

CSCvq93836

ENH: Addition of 'show logging setting' to 'show tech' output

CSCvr58708

Failover ipsec - protocol 8 IPSec SA mismatch on decaps with decrypt and verify counters

CSCvs82829

Calls fail once anyconnect configuration is added to the site to site VPN tunnel

CSCvt00113

ASA/FTD traceback and reload due to memory leak in SNMP community string

CSCvt38279

Erase disk0 on ISA3000 causes file system not supported

CSCvt60190

Cisco ASA and FTD Web Services File Upload Denial of Service Vulnerability

CSCvt80126

ASA traceback and reload for the CLI "show asp table socket 18421590 det"

CSCvt98599

IKEv2 Call Admission Statistics "Active SAs" counter out of sync with the real number of sessions

CSCvu03107

AnyConnect statistics is doubled in both %ASA-4-113019 and RADIUS accounting

CSCvu12684

HKT - Failover time increases with upgrade to 9.8.4.15

CSCvu26296

ASA interface ACL dropping snmp control-plane traffic from ASA

CSCvu32698

ASA Crashes in SNMP while joining the cluster when key config-key password-encryption" is present

CSCvu34413

SSH keys lost in ASA after reload

CSCvu38795

FTD firewall unit cannot join the cluster after a traceback due to invalid interface GOID entry

CSCvu40213

ASA traceback in Thread Name kerberos_recv

CSCvu42434

ASA: High CPU due to stuck running SSH sessions / Unable to SSH to ASA

CSCvu43924

GIADDR of DHCP Discover packet is changed to the ip address of dhcp-network-scope

CSCvu44910

Cisco ASA Software and FTD Software Web Services Cross-Site Scripting Vulnerability

CSCvu49625

[PKI] Standard Based IKEv2 Certificate Auth session does second userfromcert lookup unnecessarily

 

 

Revision:  Version 9.8(4)22 – 06/02/2020

Files:  asa984-22-smp-k8.bin, cisco-asa-fp2k.9.8.4.22.SPA, cisco-asa-fp1k.9.8.4.22.SPA, cisco-asa.9.8.4.22.SPA.csp

Defects resolved since 9.8(4)20:

 

CSCvb92169

ASA should provide better fragment-related logs and ASP drop reasons

CSCvi42008

Stuck uauth entry rejects AnyConnect user connections

CSCvm92359

Blocks exhaustion snapshot was not captured on ASA

CSCvn15387

Active unit Tracebacks in 'Thread Name: IKE Daemon'

CSCvn27043

Hostscan: LastSuccessfulInstallParams can not be detected by Hostscan

CSCvn64647

ASA traceback and reload due to tcp_retrans_timeout internal thread handling

CSCvn93683

ASA: cluster exec show commands not show all output

CSCvp76950

FTD Traceback and Reload on Lina thread for thread_logger

CSCvr19922

Cluster: BGP route may go in out of sync in some scenarios

CSCvr23986

Cisco ASA & FTD devices may reload under conditions of low memory and frequent complete MIB walks

CSCvr68146

Unable to auto-rejoin FTD cluster

CSCvs31443

ASA reporting negative memory values on "%ASA-5-321001: Resource 'memory' limit'" message

CSCvs33102

ASA/FTD may traceback and reload in Thread Name 'EIGRP-IPv4'

CSCvs33852

After upgrade to version 9.6.4.34 is not possible to add an access-group

CSCvs47283

Traffic may match an access-list incorrectly with object-group-search enabled

CSCvs63484

SAML tokens are not removed from hash table

CSCvs70260

IKEv2 vpn-filter drops traffic with implicit deny after volume based rekey collision

CSCvs73754

ASA/FTD: Block 256 size depletion caused by ARP of BVI not assigned to any physical interface

CSCvs88413

Port-channel bundling is failing after upgrade to 9.8 version

CSCvt11661

DOC - Clarify the meaning of mp-svc-flow-control under show asp drop

CSCvt11742

ASA/FTD may traceback and reload in Thread Name 'ssh'

CSCvt24328

FTD: Traceback and reload related to lina_host_file_open_raw function

CSCvt26031

ASAv Unable to register smart licensing with IPv6

CSCvt27585

Observed traceback on 2100 while performing Failover Switch from Standby.

CSCvt33785

IPSec SAs are not being created for random VPN peers

CSCvt36542

Multi-context ASA/LINA on FPR not sending DHCP release message

CSCvt41333

Dynamic RRI route is not destroyed when IKEv2 tunnel goes down

CSCvt43967

Pad packets received from RA tunnel which are less than or equal 46 bytes in length with zeros

CSCvt45863

Crypto ring stalls when the length in the ip header doesn't match the packet length

CSCvt46830

FPR2100 'show crypto accelerator statistics' counters do not track symmetric crypto

CSCvt50946

Stuck uauth entry rejects AnyConnect user connections despite fix of CSCvi42008

CSCvt51349

Fragmented packets forwarded to fragment owner are not visible on data interface captures

CSCvt52782

ASA traceback Thread name - webvpn_task

CSCvt59253

ASA 9.13.1.7  traceback and reload while processing hostscan data (process name LINA )

CSCvt64035

remote acess mib - SNMP 64 bit only reporting 4Gb before wrapping around

CSCvt64270

ASA is sending failover interface check control packets with a wrong destination mac address

CSCvt65982

Route Fallback doesn't happen on Slave unit, upon RRI route removal.

CSCvt70322

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web DoS

CSCvt73806

FTD traceback and reload on FP2120 LINA Active Box. VPN

CSCvt75241

Redistribution of VPN advertised static routes fail after reloading the FTD on FPR2100

CSCvt83121

Cisco Adaptive Security Appliance Software and Firepower Threat Defense OSPFv2 DoS

CSCvt86188

SNMP traps can't be generated via diagnostic interface

CSCvt90330

ASA traceback and reload with thread name coa_task

CSCvt92647

Connectivity over the state link configured with IPv6 addresses is lost after upgrading the ASA

CSCvu07880

ASA on QP platforms display wrong coredump filesystem space (50 GB)

CSCvu12248

ASA-FPWR 1010 traceback and reload when users connect using AnyConnect VPN

CSCvu17965

ASA generated a traceback and reloaded when changing the port value of a manual nat rule

CSCvu26561

WebVPN SSO Gives Unexpected Results when Integrated with Kerberos

 

 

Revision:  Version 9.8(4)20 – 04/06/2020

Files:  asa984-20-smp-k8.bin, cisco-asa-fp2k.9.8.4.20.SPA, cisco-asa.9.8.4.20.SPA.csp

Defects resolved since 9.8(4)15:

 

CSCvp49481

Cisco ASA Software and Cisco FTD Software SSL VPN Denial of Service Vulnerability

CSCvp57643

FP9300 Cluster - Master unit does not update all the route changes to slaves

 

CSCvp93468

Need to add inactivity timer for aware server sockets

CSCvr15503

ASA: SSH and ASDM sessions stuck in CLOSE_WAIT causing lack of MGMT for the ASA

 

CSCvr50509

Some 3DES related configurations are lost after booted

 

CSCvs07668

FTD traceback and reload on thread DATAPATH-1-15076 when SIP inspection is enabled

 

CSCvs52169

ASA sends malformed RADIUS message when device-id from AnyConnect is too long

 

CSCvs59056

ASA/FTD Tunneled Static Routes are Ignored by Suboptimal Lookup if Float-Conn is Enabled

 

CSCvs73663

ASA Traceback on IPsec message handler Thread

 

CSCvs77818

Traceback: spin_lock_fair_mode_enqueue: Lock (np_conn_shrlock_t) is held for a long time

 

CSCvs79023

ASA/FTD Traceback in Thread Name: DATAPATH due to DNS inspection

 

CSCvs80157

ASA Traceback Thread Name: IKE Daemon

 

CSCvs90100

ASA/FTD may traceback and reload in Thread Name 'License Thread'

 

CSCvs97863

Reduce number of fsync calls during close in flash file system

 

CSCvs97908

Invalid scp session terminates other active http, scp sessions

 

CSCvt02409

Cisco Firepower Threat Defense Software Inline Pair/Passive Mode DoS Vulnerability

 

CSCvt03598

Cisco ASA Local File Reading Vulnerability

 

CSCvt05862

IPv6 DNS server resolution fails when the server is reachable over the management interface.

 

CSCvt12463

ASA: Traceback in thread Unicorn Admin Handler

 

CSCvt15163

Cisco ASA and FTD Software Web Services Information Disclosure Vulnerability

CSCvt18028

Cisco ASA and FTD WebVPN CRLF Injection Vulnerability

 

CSCvt21041

FTD Traceback in thread 'ctm_ipsec_display_msg'

 

CSCvt25225

ASA: Active unit HA traceback and reload during Config Sync state during OSPF sync

 

CSCvt28182

sctp-state-bypass is not getting invoked for inline FTD

 

CSCvt35945

Encryption-3DES-AES should not be required when enabling ssh version 2 on 9.8 train

 

 

 

Revision:  Version 9.8(4)17 – 02/21/2020

Files:  asa984-17-smp-k8.bin, cisco-asa-fp2k.9.8.4.17.SPA, cisco-asa.9.8.4.17.SPA.csp

Defects resolved since 9.8(4)15:

 

CSCuy53106

ASA OS incorrectly calculates certificate expiry date in Syslog 717054

CSCvg59385

ASA scansafe connector takes too long to failover to secondary CWS Tower

CSCvj93609

ASA traceback on spin_lock_release_actual

CSCvn67137

ASA may slowly leak memory when using NetFlow

CSCvn75368

IPsec VPN goes down intermittently during a re-key

CSCvo80853

UDP flood causes Lina to run out of memory if blocked

CSCvp67033

ASAv v9.12(1) cannot distinguish name aliases for IPv6

CSCvq37913

VPN-sessiondb does not replicate to standby ASA

CSCvq61601

OpenSSL vulnerability CVE-2019-1559 on FTD

CSCvq78126

V route is missing even after setting the reverse route in Crypto map config in HA-IKEv2

CSCvq79913

ICMP error packets being dropped for Null pdts_info

CSCvq95826

DCD Causes Standby to send probes

CSCvr13278

PPPoE session not coming up after reload.

CSCvr42344

Traceback on snp_policy_based_route_lookup when deleting a rule from access-list configured for PBR

CSCvr50630

ASA Traceback: SCTP bulk sync and HA synchronization

CSCvr71878

IPSEC SA is deleted by failover which is caused by link down (9.8.x train fix)

CSCvr86077

ASA Traceback/pagefault in Datapath due to re_multi_match_ascii

CSCvr92311

Standby ASA logging %ASA-4-720022: (VPN-Secondary) Cannot find trust point __tmpCiscoM1Root__

CSCvr92327

ASA/FTD may traceback and reload in Thread Name 'PTHREAD-1533'

CSCvr93978

ASA traceback and reload on Thread DATAPATH-0-2064

CSCvs02954

ASA OSPF: Prefix removed from the RIB when topology changes, then added back when another SPF is run

CSCvs03023

Clustering module needs to skip the hardware clock update to avoid the timeout error and clock jump

CSCvs04179

ASA - 9.8.4.12 traceback and reload in ssh or fover_rx Thread

CSCvs05262

Decrement TTL display wrong result

CSCvs07982

ASA TRACEBACK: sctpProcessNextSegment - SCTP_INIIT_CHUNK

CSCvs10748

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web DoS

CSCvs15276

ERROR: entry for ::/0 exists when configuring ipv6 icmp

CSCvs27264

mroute entries on ASA not getting refreshed.

CSCvs28213

ASA Traceback in Thread Name SSH with assertion slib_malloc.c

CSCvs28580

Lina crashing  continously in latest release

CSCvs29779

ASA may traceback and reload while waiting for "DATAPATH-12-1899" process to finish.

CSCvs35853

FTD-HA: Deploy fail when interface as used inline-pair in standby unit is down

CSCvs39589

ASA doesn't honor SSH Timeout When Data Channel is not Negotiated

CSCvs43154

Secondary ASA is unable to join the failover due to aggressive warning messages.

CSCvs45548

reactivation-mode timed causing untimely reactivation of failed server

CSCvs50459

Cisco ASA and Cisco FTD Malformed OSPF Packets Processing Denial of Service Vulnerability

 

 

Revision:  Version 9.8(4)15 – 12/02/2019

Files:  asa984-15-smp-k8.bin, cisco-asa-fp2k.9.8.4.15.SPA, cisco-asa.9.8.4.15.SPA.csp

Defects resolved since 9.8(4)12:

 

CSCvh73143

DP threads starves of CPU and traceback and reloads due to single spin lock for syslog processing

 

CSCvo76866

Traceback on 2100 - watchdog

 

CSCvp29554

Watchdog traceback due to lina_host_file_stat calls

 

CSCvq50587

ASA/FTD may traceback and reload in Thread Name 'BGP Router'

 

CSCvq50944

OSPFv3 neighborship is flapping every ~30 minutes

 

CSCvq51284

FPR 2100, low block  9472 causes packet loss through the device.

 

CSCvq55426

Adding an ipv6 default route causes CLI to hang for 50 seconds

 

CSCvq65864

Traceback in HTTP Cli Exec when upgrading to 96.4.0.41

 

CSCvq73534

Cisco ASA Software Kerberos Authentication Bypass Vulnerability

CSCvq75634

Management interface configuration leads to immediate traceback and reload

 

CSCvq87797

Multiple context  5585 ASA, transparent context losing management interface configuration.

 

CSCvr10777

ASA Traceback in Ikev2 Daemon

 

CSCvr23580

Can't delete 2 or more than two IP address-pool

 

CSCvr25768

ASA may traceback on display_hole_og

 

CSCvr27445

App-sync failure if unit tries to join HA during policy deployment

 

CSCvr30718

VRF:bgp route not syncing to slave units when there is route change

 

CSCvr50266

Dual stack ASAv failover triggered by reload issue

 

CSCvr54794

ASA Standby after a reload and being active requests and caches smart license entitlements

 

CSCvr55400

FTD/LINA traceback and reload observed in thread name: cli_xml_server

 

CSCvr55518

Missing clean up on rule creation failure.

 

CSCvr57605

ASA after reload had license context count greater than platform limits

 

CSCvr58103

ISA3k might enter in boot loop after upgrade to certain versions

 

CSCvr60111

configurations getting wiped off from standby, while deployment fails on active

 

CSCvr66768

Lina Traceback during FTD deployment when PBR config is being pushed

 

CSCvr74828

Plaintext passwords logged in asa-appagent.log during bootstrap configuration create/edits

 

CSCvr85295

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Code Execution Vulnerability

 

 

 

Revision:  Version 9.8(4)12 – 10/29/2019

Files:  asa984-12-smp-k8.bin, cisco-asa-fp2k.9.8.4.12.SPA, cisco-asa.9.8.4.12.SPA.csp

Defects resolved since 9.8(4)10:

 

CSCva36446

ASA Stops Accepting Anyconnect Sessions/Terminates Connections Right After Successful SSL handshake

CSCvp69229

OpenSSL 0-byte Record Padding Oracle Information Disclosure Vulnerabil

CSCvp80775

Unsupported runtime JavaScript exception handling in the client side WebVPN rewriter

CSCvq15976

ASA Memory Leak - snp_svc_insert_dtls_session

CSCvq57591

When only IP communication is disrupted on failover link LANTEST msg is not sent on data interfaces

CSCvq63024

Dual stacked ASAv manual failover issues

CSCvq64742

ASA5515-K9 standby traceback in Thread Name ssh

CSCvq69111

Traceback: Cluster unit lina assertion in thread name:Cluster controller

CSCvq70468

ASA cluster does not flush OSPF routes

CSCvq75743

ASA:BGP recursive route lookup for destination 3 hop away  is failing.

CSCvq77547

Connections fail to replicate in failover due to failover descriptor mis-match on port-channels

CSCvq80318

ASA generates incorrect error message about PCI cfg space when enumerating Internal-Data0/1

CSCvq80735

Cannot add neighbor in BGP when the neighbor is on the same subnet as one interface

CSCvq87703

Active device is not reporting correct peer state.

CSCvq91645

Flow Offload Hashing Change of Behavior

CSCvq92126

ASA traceback in Thread IPsec Message Handler

CSCvr07419

Cisco ASA and FTD Software IPv6 DNS Denial of Service Vulnerability

 

CSCvr12018

ASA: VPN traffic fails to take the tunnel route when the default route is learnt over BGP.

CSCvr25954

FTD/LINA Standby may traceback and reload during logging command replication from Active

 

 

Revision:  Version 9.8(4)10 – 08/29/2019

Files:  asa984-10-smp-k8.bin, cisco-asa-fp2k.9.8.4.10.SPA, cisco-asa.9.8.4.10.SPA.csp

Defects resolved since 9.8(4)8:

 

CSCvj98964

ASA may traceback due to SCTP traffic

 

CSCvm40288

Port-Channel issues on HA link

 

CSCvn77388

SDI - SUSPENDED servers cause 15sec delay in the completion of a authentication with a good server

 

CSCvo11280

ASA Enhancement: Generate syslog message once member of the SDI cluster changes state

 

CSCvo28118

Traceback in VPN Clustering HA timer thread when member tries to join the cluster

 

CSCvo73250

ENH: ACE details for warning "found duplicate element"

 

CSCvo74397

ENH: Add process information to "Command Ignored, configuration in progress..."

 

CSCvo83169

Cisco ASA Software and FTD Software FTP Inspection Denial of Service Vulnerability

 

CSCvo86038

Simultaneous FINs on flow-offloaded flows lead to stale conns

 

CSCvp04134

Traceback in HTTP Cli Exec when upgrading to 9.12.1

 

CSCvp04186

cts import-pac tftp: syntax does not work

 

CSCvp12582

Option to display port number on access-list instead of well known port name on ASA

 

CSCvp33341

Cisco ASA and Firepower Threat Defense Software WebVPN Cross-Site Scripting Vulnerability

CSCvp55901

LINA traceback on ASA in HA Active Unit repeatedly

 

CSCvp76944

Cisco ASA and FTD Software WebVPN CPU Denial of Service Vulnerability

CSCvp84546

ASA 9.9.2 Clientless WebVPN - HTML entities are incorrectly decoded when processing HTML

CSCvq01459

LINA Traceback after upgrade to 9.12.2.1

CSCvq05113

ASA failover LANTEST messages are sent on first 10 interfaces in the configuration.

CSCvq11513

Traceback: "saml identity-provider" command will crash multi-context ASAs

CSCvq12070

Not able to establish more than 2 simultaneous ASDM sessions

CSCvq12411

ASA may traceback due to SCTP traffic despite fix CSCvj98964

CSCvq13442

When deleting context the ssh key-exchange goes to Default GLOBALLY!

CSCvq21607

ssl trust-point command will be removed when restoring backup via CLI

CSCvq25626

Watchdog on ASAv when logging to buffer

CSCvq27010

Memory leak observed when ASA-SFR dataplane communication flaps

CSCvq28250

ENH: ASA Cluster debug for syn cookie issues

CSCvq39317

ASA  is unable to verify the file integrity

CSCvq44665

FTD/ASA : Traceback in Datapath with assert snp_tcp_intercept_assert_disabled

CSCvq54667

SSL VPN may not be able to establish due to SSL negotiation issue

CSCvq60131

ASA traceback observed when moving EZVPN spokes to the device.

CSCvq65241

ASA Traceback on Saleen in Thread Name: IPv6 IDB

 

 

Revision:  Version 9.8(4)8 – 07/17/2019

Files:  asa984-8-smp-k8.bin, cisco-asa-fp2k.9.8.4.8.SPA, cisco-asa.9.8.4.8.SPA.csp

Defects resolved since 9.8(4)7:

 

CSCvh62779

Multi-context - IKEv2 SA fail to establish

 

CSCvj61580

ASA traceback with Thread: DATAPATH-8-2035

 

CSCvo14961

ASA may traceback and reload while waiting for "dns_cache_timer" process to finish.

 

CSCvo47390

ASA traceback in thread SSH

 

CSCvo68184

management-only of diagnostic I/F on secondary FTD get disappeared

 

CSCvo90998

LACPDUs should not be sent to snort for inline-set interfaces

 

CSCvo97979

The delay command in interface configuration is modified after rebooted

 

CSCvp10132

AnyConnect connections fail with TCP connection limit exceeded error

 

CSCvp16536

ASA traceback and reload observed in Datapath due to SIP inspection.

 

CSCvp35141

ASA sends invalid redirect response for POST request

 

CSCvp35384

IKEv2 RA Generic client - stuck outgoing asp table entry - traffic encrypted with stale SPI

 

CSCvp43066

DHCP NACK silently dropped by ASA sent from DHCP server if configured as DHCP relay

 

CSCvp49790

Cisco ASA Software and FTD Software OSPF LSA Processing Denial of Service Vulnerability

CSCvp63068

Thread Name: CP DP SFR Event Processing traceback

 

CSCvp70699

ASA Failover split brain (both units active) after rebooting a Firepower chassis

 

CSCvp71180

MCA+AAA+OTP with RADIUS challenge fails to send aggauth handle in challenge

 

CSCvp91296

Firepower 4100 connection counts mismatch between active and standby ASA

 

 

 

Revision:  Version 9.8(4)7 – 06/04/2019

Files:  asa984-7-smp-k8.bin, cisco-asa-fp2k.9.8.4.7.SPA, cisco-asa.9.8.4.7.SPA.csp

Defects resolved since 9.8(4)3:

 

CSCvh13869

ASA IKEv2 unable to open aaa session: session limit [2048] reached

 

CSCvi47523

SSP-NTP: ssp-ntp script monitoring script enhancements for XRU, KP

 

CSCvj90428

Clock sync issue on ASA with FXOS

 

CSCvk22322

ASA Traceback (watchdog timeout) when syncing config from active unit (inc. cachefs_umount)

 

CSCvn25970

Traceback in Firepower 4120

 

CSCvn76875

Graceful Restart BGP does not work intermittently

 

CSCvn86777

Deployment on FTD with low memory results on interface nameif to be removed

 

CSCvo31695

Traceback in threadname DATAPATH-0-1668 while freeing memory block

 

CSCvo45755

ASA SCP transfer to box stall mid-transfer

 

CSCvo60580

ASA traceback and reloads when issuing "show inventory" command

 

CSCvo65741

ASA: BGP routes is cleared on routing table after failover occur and bgp routes are changed

 

CSCvo66920

Enhancement: add counter for Duplicate remote proxy

 

CSCvo80501

Standby Firewall reloads with a traceback upon doing a manual failover

 

CSCvo90153

ASA unable to authenticate users with special characters via https

 

CSCvp12052

ASA may traceback and reload. suspecting webvpn related

 

CSCvp16482

ASA on FXOS platforms reloads when establishing simultaneous ASDM sessions

 

CSCvp16945

Cisco ASA Software and FTD Software MGCP Denial of Service Vulnerabilities

CSCvp16949

Cisco ASA Software and FTD Software MGCP Denial of Service Vulnerabilities

CSCvp18878

ASA: Watchdog traceback in Datapath

 

CSCvp19549

FTD lina cored with Thread name: cli_xml_server

 

CSCvp24728

Random SGT tags added by FTD

 

CSCvp29692

FIPS mode gets disabled after rollback from a failed policy deploy

 

CSCvp32617

established tcp does not work post 9.6.2

 

CSCvp45882

Cisco ASA Software and FTD Software SIP Inspection Denial of Service Vulnerability

 

CSCvp67392

ASA/FTD HA Data Interface Heartbeat dropped due to Reverse Path Check

 

 

 

Revision:  Version 9.8(4)3 – 05/14/2019

Files:  asa984-3-smp-k8.bin, cisco-asa-fp2k.9.8.4.3.SPA, cisco-asa.9.8.4.3.SPA.csp

Defects resolved since 9.8(4):

 

CSCvp36425

ASA 5506/5508/5516 traceback in Thread Name octnic_hm_thread