Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

 

Revision:  Version 9.12(2)9 – 10/02/2019

Files:  asa9122-9-smp-k8.bin, cisco-asa-fp2k.9.12.2.9.SPA, cisco-asa.9.12.2.9.SPA.csp

Defects resolved since 9.12(2)5:

 

CSCvn77388

SDI - SUSPENDED servers cause 15sec delay in the completion of a authentication with a good server

CSCvo11280

ASA Enhancement: Generate syslog message once member of the SDI cluster changes state

CSCvo28118

Traceback in VPN Clustering HA timer thread when member tries to join the cluster

CSCvo43795

OSPF Process ID doesnot change even after clearing OSPF process

CSCvo73250

ENH: ACE details for warning "found duplicate element"

CSCvo74397

ENH: Add process information to "Command Ignored, configuration in progress..."

CSCvp04186

cts import-pac tftp: syntax does not work

CSCvp12582

Option to display port number on access-list instead of well known port name on ASA

CSCvp23109

ASA HA IKEv2 generic RA - AnyConnect Premium All In Use incorrect on standby

CSCvp33341

Cisco ASA and Firepower Threat Defense Software WebVPN Cross-Site Scripting Vulnerability

CSCvp55901

LINA traceback on ASA in HA Active Unit repeatedly

CSCvp76944

Cisco ASA and FTD Software WebVPN CPU Denial of Service Vulnerability

CSCvp85736

Cluster master reload cause ping failure to the Management virtual IP

CSCvq05113

ASA failover LANTEST messages are sent on first 10 interfaces in the configuration.

CSCvq17263

FTD LINA traceback at DATAPATH-8-15821

CSCvq24494

FP2100 - Flow oversubscribing ring/CPU core causing disruption to working flows on FP2100 platforms

CSCvq28250

ENH: ASA Cluster debug for syn cookie issues

CSCvq39317

ASA  is unable to verify the file integrity

CSCvq44665

FTD/ASA : Traceback in Datapath with assert snp_tcp_intercept_assert_disabled

CSCvq54667

SSL VPN may not be able to establish due to SSL negotiation issue

CSCvq57591

When only IP communication is disrupted on failover link LANTEST msg is not sent on data interfaces

CSCvq60131

ASA traceback observed when moving EZVPN spokes to the device.

CSCvq63024

Dual stacked ASAv manual failover issues

CSCvq64742

ASA5515-K9 standby traceback in Thread Name ssh

CSCvq65241

ASA Traceback on Saleen in Thread Name: IPv6 IDB

CSCvq69111

Traceback: Cluster unit lina assertion in thread name:Cluster controller

CSCvq70468

ASA cluster does not flush OSPF routes

CSCvq70775

FPR2100 FTD Standby unit leaking 9K blocks

CSCvq75743

ASA:BGP recursive route lookup for destination 3 hop away  is failing.

CSCvq77547

Connections fail to replicate in failover due to failover descriptor mis-match on port-channels

CSCvq80318

ASA generates incorrect error message about PCI cfg space when enumerating Internal-Data0/1

CSCvq80735

Cannot add neighbor in BGP when the neighbor is on the same subnet as one interface

CSCvq91645

Flow Offload Hashing Change of Behavior

CSCvq92126

ASA traceback in Thread IPsec Message Handler

 

 

Revision:  Version 9.12(2)5 – 08/26/2019

Files:  cisco-asa-fp2K.9.12.2.5.SPA

Defects resolved since 9.12(2)4:

 

CSCvq91211

FP2100: Upgrade or new install attempts to 9.12.2.4 results in ASA application start failures

 

Note: The 9.12.2.5 interim release is only needed for Firepower 2100 platforms.  Other ASA platforms do not require this fix.

 

 

Revision:  Version 9.12(2)4 – 08/06/2019

Files:  asa9122-4-smp-k8.bin, cisco-asa-fp2k.9.12.2.4.SPA, cisco-asa.9.12.2.4.SPA.csp

Defects resolved since 9.12(2)1:

 

CSCvj61580

ASA traceback with Thread: DATAPATH-8-2035

CSCvj98964

ASA may traceback due to SCTP traffic

CSCvm40288

Port-Channel issues on HA link

CSCvn78593

Control-plane ACL doesn't work correctly on FTD

CSCvo14961

ASA may traceback and reload while waiting for "dns_cache_timer" process to finish.

CSCvo83169

Cisco ASA Software and FTD Software FTP Inspection Denial of Service Vulnerability

CSCvo86038

Simultaneous FINs on flow-offloaded flows lead to stale conns

CSCvo90998

LACPDUs should not be sent to snort for inline-set interfaces

CSCvp04134

Traceback in HTTP Cli Exec when upgrading to 9.12.1

CSCvp10132

AnyConnect connections fail with TCP connection limit exceeded error

CSCvp35141

ASA sends invalid redirect response for POST request

CSCvp35384

IKEv2 RA Generic client - stuck outgoing asp table entry - traffic encrypted with stale SPI

CSCvp43066

DHCP NACK silently dropped by ASA sent from DHCP server if configured as DHCP relay

CSCvp55880

Fail-Closed FTD passes packets through on Snort processes down

CSCvp66559

Deploy fails on FTD HA due to exception when parsing big xml response

CSCvp70699

ASA Failover split brain (both units active) after rebooting a Firepower chassis

CSCvp71180

MCA+AAA+OTP with RADIUS challenge fails to send aggauth handle in challenge

CSCvp80775

Unsupported runtime JavaScript exception handling in the client side WebVPN rewriter

CSCvp84546

ASA 9.9.2 Clientless WebVPN - HTML entities are incorrectly decoded when processing HTML

CSCvp91296

Firepower 4100 connection counts mismatch between active and standby ASA

CSCvp97916

Executing 'failover' twice on active unit, clears interface configuration on standby unit

CSCvq00005

FTD traceback and reload on LINA thread

CSCvq11513

Traceback: "saml identity-provider" command will crash multi-context ASAs

CSCvq12070

Not able to establish more than 2 simultaneous ASDM sessions

CSCvq12411

ASA may traceback due to SCTP traffic despite fix CSCvj98964

CSCvq13442

When deleting context the ssh key-exchange goes to Default GLOBALLY!

CSCvq21607

ssl trust-point command will be removed when restoring backup via CLI

CSCvq24134

ASA IKEv2 - ASA sends additional delete message after initiating a phase 2 rekey

CSCvq25626

Watchdog on ASAv when logging to buffer

CSCvq27010

Memory leak observed when ASA-SFR dataplane communication flaps

 

 

Revision:  Version 9.12(2)1 – 06/25/2019

Files:  asa9122-1-smp-k8.bin, cisco-asa-fp2k.9.12.2.1.SPA, cisco-asa.9.12.2.1.SPA.csp

Defects resolved since 9.12(2):

 

CSCvf83160

Traceback on Thread Name: DATAPATH-2-1785

CSCvh13869

ASA IKEv2 unable to open aaa session: session limit [2048] reached

CSCvi47523

SSP-NTP: ssp-ntp script monitoring script enhancements for XRU, KP

CSCvj01704

ASA is getting traceback with reboot only on Spyker aftr shutdown SFR module

CSCvk22322

ASA Traceback (watchdog timeout) when syncing config from active unit (inc. cachefs_umount)

CSCvk29685

Traceback in DATAPATH on ASA

CSCvm36362

Route tracking failure

CSCvm39901

ENH: ASA - support for more than 4 servers in multiple mode.

CSCvm64400

IKEv2: IKEv2-PROTO-2: Failed to allocate PSH from platform

CSCvm70274

tcp proxy: ASA traceback on DATAPATH

CSCvn25970

Traceback in Firepower 4120

CSCvn76875

Graceful Restart BGP does not work intermittently

CSCvn78870

ASA Multicontext traceback and reload due to allocate-interface out of range command

CSCvn86777

Deployment on FTD with low memory results on interface nameif to be removed

CSCvo03700

ASA may traceback in thread logger when cluster is enabled on slave unit

CSCvo17775

EIGRP breaks when new sub-interface is added and "mac-address auto" is enabled

CSCvo31695

Traceback in threadname DATAPATH-0-1668 while freeing memory block

CSCvo41572

FMC shows connection events with packet count as 0

CSCvo45755

ASA SCP transfer to box stall mid-transfer

CSCvo47390

ASA traceback in thread SSH

CSCvo47562

VPN sessions failing due to PKI handles not freed during rekeys

CSCvo48838

Lina does not properly report the error for configuration line that is too long

CSCvo51265

SCP large file transfer to the box result in a traceback

CSCvo58847

Enhancement to address high IKE CPU seen due to tunnel replace scenario

CSCvo60580

ASA traceback and reloads when issuing "show inventory" command

CSCvo62031

ASA Traceback and reload while running IKE Debug

CSCvo65741

ASA: BGP routes is cleared on routing table after failover occur and bgp routes are changed

CSCvo66534

Traceback and reload citing Datapath as affected thread

CSCvo66920

Enhancement: add counter for Duplicate remote proxy

CSCvo67421

easyVPN got broke on lina_dev [201.4.1.106]

CSCvo68184

management-only of diagnostic I/F on secondary FTD get disappeared

CSCvo72462

Do not decrypt rule causes traffic interruptions.

CSCvo74350

ASA may traceback and reload. Potentially related to WebVPN traffic

CSCvo80501

Standby Firewall reloads with a traceback upon doing a manual failover

CSCvo87930

HTTP with ipv6 using w3m is failing

CSCvo87985

ASA sends password in plain text for "copy" command

CSCvo90153

ASA unable to authenticate users with special characters via https

CSCvo97979

The delay command in interface configuration is modified after rebooted

CSCvp07143

DTLS 1.2 and AnyConnect oMTU

CSCvp12052

ASA may traceback and reload. suspecting webvpn related

CSCvp14674

ASAv Azure: Route table BGP propagation setting reset when ASAv fails over

CSCvp16536

ASA traceback and reload observed in Datapath due to SIP inspection.

CSCvp18878

ASA: Watchdog traceback in Datapath

CSCvp19549

FTD lina cored with Thread name: cli_xml_server

CSCvp24728

Random SGT tags added by FTD

CSCvp29692

FIPS mode gets disabled after rollback from a failed policy deploy

CSCvp32617

established tcp does not work post 9.6.2

CSCvp38530

Unable to configure more than 100 aaa-server group limit reached

CSCvp45882

Cisco ASA Software and FTD Software SIP Inspection Denial of Service Vulnerability

CSCvp49790

Cisco ASA Software and FTD Software OSPF LSA Processing Denial of Service Vulnerability

CSCvp59864

IP Address stuck in local pool and showing as "In Use" even when the AnyConnect client disconnects

CSCvp63068

Thread Name: CP DP SFR Event Processing traceback

CSCvp67392

ASA/FTD HA Data Interface Heartbeat dropped due to Reverse Path Check

CSCvp70020

After reboot, "ssh version 1 2" added to running-config

CSCvp72412

Time zone in syslogs  messages