Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 9.12(3)12 – 04/21/2020

Files:  asa9123-12-smp-k8.bin, cisco-asa-fp1k.9.12.3.12.SPA, cisco-asa-fp2k.9.12.3.12.SPA, cisco-asa.9.12.3.12.SPA.csp

Defects resolved since 9.12(3)9:

 

CSCuw51499

TCM doesn't work for ACE addition/removal, ACL object/object-group edits

CSCvr50509

Some 3DES related configurations are lost after booted

CSCvr58411

RRI on static HUB/SPOKE config is not working on HUB when a new static SPOKE is added or deleted

CSCvs01422

Lina traceback when changing device mode of FTD

CSCvs09533

FP2100 Traceback and reload when processing traffic through more than two inline sets

CSCvs33852

After upgrade to version 9.6.4.34 is not possible to add an access-group

CSCvs47252

ASA traceback and reload when running command "clear capture /"

CSCvs55603

ICMP Reply Dropped when matched by ACL

CSCvs59056

ASA/FTD Tunneled Static Routes are Ignored by Suboptimal Lookup if Float-Conn is Enabled

CSCvs63484

SAML tokens are not removed from hash table

CSCvs80536

FP41xx  incorrect interface applied in ASA capture

CSCvs90100

ASA/FTD may traceback and reload in Thread Name 'License Thread'

CSCvt02409

9.12.2.151 snp_cluster_ingress traceback on FPR9300 3-node cluster nested VLAN traffic

CSCvt05862

IPv6 DNS server resolution fails when the server is reachable over the management interface.

CSCvt06606

Flow offload not working with combination of FTD 6.2(3.10) and FXOS 2.6(1.169)

CSCvt06841

Incorrect access-list hitcount seen when configuring it with a capture on ASA

CSCvt11661

DOC - Clarify the meaning of mp-svc-flow-control under show asp drop

CSCvt12463

ASA: Traceback in thread Unicorn Admin Handler

CSCvt23643

VPN failover recovery is taking approx. 30 seconds for data to resume

CSCvt24328

FTD: Traceback and reload related to lina_host_file_open_raw function

CSCvt25225

ASA: Active unit HA traceback and reload during Config Sync state during OSPF sync

CSCvt26031

ASAv Unable to register smart licensing with IPv6

CSCvt26067

Active FTP fails when secondary interface is used on FTD

CSCvt27585

Observed Crash in KP while performing Failover Switch from Standby.

CSCvt28182

sctp-state-bypass is not getting invoked for inline FTD

CSCvt33785

IPSec SAs are not being created for random VPN peers

CSCvt46289

ASA LDAPS connection fails on firepower 1010

CSCvt46830

FPR2100 'show crypto accelerator statistics' counters do not track symmetric crypto

CSCvt51987

Traffic outage due to 80 size block exhaustion on the ASA

CSCvt64035

remote acess mib - SNMP 64 bit only reporting 4Gb before wrapping around

CSCvt68294

Adjust Firepower 4120 Maximum VPN Session Limit to 20,000

 

 

Revision:  Version 9.12(3)9 – 03/19/2020

Files:  asa9123-9-smp-k8.bin, cisco-asa-fp2k.9.12.3.9.SPA, cisco-asa.9.12.3.9.SPA.csp

Defects resolved since 9.12(3)7:

 

CSCvm77115

Lina Traceback due to invalid TSC values

CSCvp57643

FP9300 Cluster - Master unit does not update all the route changes to slaves

CSCvp93468

Need to add inactivity timer for aware server sockets

CSCvr07460

ASA traceback and reload related to crypto PKI operation

 

CSCvr15503

ASA: SSH and ASDM sessions stuck in CLOSE_WAIT causing lack of MGMT for the ASA

 

CSCvr56031

FTD/LINA Traceback and reload observed in thread name: cli_xml_server

 

CSCvr90965

FTDv Deployment in Azure causes unrecoverable traceback state due to no dns domain-lookup any"

 

CSCvr93978

ASA traceback and reload on Thread DATAPATH-0-2064

 

CSCvs03023

Clustering module needs to skip the hardware clock update to avoid the timeout error and clock jump

 

CSCvs07668

FTD traceback and reload on thread DATAPATH-1-15076 when SIP inspection is enabled

 

CSCvs16073

snmp poll failure with host and host-group configured

 

CSCvs27264

mroute entries on ASA not getting refreshed.

 

CSCvs28580

Traceback when processing SSL traffic under heavy load

 

CSCvs31470

OSPF Hello causing 9K block depletion, control point CPU 100% and cluster unstable.

 

CSCvs38785

Inconsistent timestamp format in syslog

 

CSCvs40230

ICMP not working and failed with inspect-icmp-seq-num-not-matched

 

CSCvs43154

Secondary ASA is unable to join the failover due to aggressive warning messages.

 

CSCvs52169

ASA sends malformed RADIUS message when device-id from AnyConnect is too long

 

CSCvs59966

false reported value for OID "cipSecGlobalActiveTunnels" - same as ASDM

 

CSCvs73663

ASA Traceback on IPsec message handler Thread

 

CSCvs76605

Wrong Module version listed for FXOS 2.6(1.174)

 

CSCvs77818

Traceback: spin_lock_fair_mode_enqueue: Lock (np_conn_shrlock_t) is held for a long time

 

CSCvs79023

ASA/FTD Traceback in Thread Name: DATAPATH due to DNS inspection

 

CSCvs80157

ASA Traceback Thread Name: IKE Daemon

 

CSCvs82726

Placeholder to address CSCvs31470 in Multi-Context Mode

 

CSCvs91389

FTD Traceback Lina process

 

CSCvs97863

Reduce number of fsync calls during close in flash file system

 

CSCvs97908

Invalid scp session terminates other active http, scp sessions

 

CSCvt01397

Deployment is marked as success although LINA config was not pushed

 

CSCvt15163

Cisco ASA and FTD Software Web Services Information Disclosure Vulnerability

CSCvt21041

FTD Traceback in thread 'ctm_ipsec_display_msg'

 

 

 

Revision:  Version 9.12(3)7 – 03/03/2020

Files:  asa9123-7-smp-k8.bin, cisco-asa-fp2k.9.12.3.7.SPA, cisco-asa.9.12.3.7.SPA.csp

Defects resolved since 9.12(3)2:

 

CSCuj60109

ENH: SFP transceivers attached to ASA-IC-6GE-SFP-A are not shown by CLI

 

CSCvg59385

ASA scansafe connector takes too long to failover to secondary CWS Tower

 

CSCvo80853

UDP flood causes Lina to run out of memory if blocked

CSCvp70833

ASA/FTD: Twice nat Rule with same service displaying error "ERROR: NAT unable to reserve ports"

 

CSCvq61601

OpenSSL vulnerability CVE-2019-1559 on FTD

 

CSCvq99107

Hot swap of SFP is not taking effect on the ASA

 

CSCvr20449

Policy deployment is reported as successful on the FMC but it is actually failed

 

CSCvr20876

low memory causes kernel to invoke - oom and reload device - modified rlimit for KP

 

CSCvr35125

Packet loss over failover link triggers Split-Brain

 

CSCvr42344

Traceback on snp_policy_based_route_lookup when deleting a rule from access-list configured for PBR

 

CSCvr50630

ASA Traceback: SCTP bulk sync and HA synchronization

 

CSCvr92311

Standby ASA logging %ASA-4-720022: (VPN-Secondary) Cannot find trust point __tmpCiscoM1Root__

 

CSCvr92327

ASA/FTD may traceback and reload in Thread Name 'PTHREAD-1533'

 

CSCvs07982

ASA TRACEBACK: sctpProcessNextSegment - SCTP_INIIT_CHUNK

 

CSCvs15972

Network Performance Degradation when SSL policy is enabled

 

CSCvs28213

ASA Traceback in Thread Name SSH with assertion slib_malloc.c

 

CSCvs29779

ASA may traceback and reload while waiting for "DATAPATH-12-1899" process to finish.

 

CSCvs39589

ASA doesn't honor SSH Timeout When Data Channel is not Negotiated

 

CSCvs40531

AnyConnect 4.8 is not working on the FPR1000 series

 

CSCvs45548

reactivation-mode timed causing untimely reactivation of failed server

 

CSCvs50459

Cisco ASA and Cisco FTD Malformed OSPF Packets Processing Denial of Service Vulnerability

CSCvs91869

IKEv1 on FTD stuck in either "MM_START" or "MM_FREE" state

 

 

Revision:  Version 9.12(3)2 – 12/20/2019

Files:  asa9123-2-smp-k8.bin, cisco-asa-fp2k.9.12.3.2.SPA, cisco-asa.9.12.3.2.SPA.csp

Defects resolved since 9.12(3):

 

CSCuy53106

ASA OS incorrectly calculates certificate expiry date in Syslog 717054

 

CSCvg59385

ASA scansafe connector takes too long to failover to secondary CWS Tower

 

CSCvj93609

ASA traceback on spin_lock_release_actual

 

CSCvm85823

Not able to ssh, ssh_exec: open(pager) error on console

 

CSCvo76866

Traceback on 2100 - watchdog

 

CSCvp04134

Traceback in HTTP Cli Exec when upgrading to 9.12.1

 

CSCvp67033

ASAv v9.12(1) cannot distinguish name aliases for IPv6

 

CSCvq12070

Not able to establish more than 2 simultaneous ASDM sessions

 

CSCvq34340

FTD traffic outage due to 9344 block size depletion caused by the egress-optimization feature

 

CSCvq37913

VPN-sessiondb does not replicate to standby ASA

 

CSCvq46587

After failover, Active unit tcp sessions are not removed when timeout reached

 

CSCvq50587

ASA/FTD may traceback and reload in Thread Name 'BGP Router'

 

CSCvq50944

OSPFv3 neighborship is flapping every ~30 minutes

 

CSCvq51284

FPR 2100, low block  9472 causes packet loss through the device.

 

CSCvq55426

Adding an ipv6 default route causes CLI to hang for 50 seconds

 

CSCvq61523

FP1000:  AnyConnect-Parent SSL-Tunnel continuously reconnecting

 

CSCvq70536

Firepower Threat Defense:not clearing BGP's NSF configuration when we break HA

 

CSCvq73534

Cisco ASA Software Kerberos Authentication Bypass Vulnerability

CSCvq76198

Traffic interruptions for FreeBSD systems

 

CSCvq78126

V route is missing even after setting the reverse route in Crypto map config in HA-IKEv2

 

CSCvq87797

Multiple context  5585 ASA, transparent context losing mangement interface configuration.

 

CSCvq88644

Traceback in tcp-proxy

CSCvq89361

Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability

CSCvr13278

PPPoE session not coming up after reload.

CSCvr21803

Mac address flap on switch with wrong packet injected on ingress FTD interface

CSCvr30718

VRF:bgp route not syncing to slave units when there is route change

CSCvr51998

ASA Static route disappearing from asp table after learning default route via BGP

CSCvr54054

Mac Rewrite Occurring for Identity Nat Traffic

CSCvr55400

FTD/LINA traceback and reload observed in thread name: cli_xml_server

CSCvr55518

Missing clean up on rule creation failure.

CSCvr57605

ASA after reload had license context count greater than platform limits

CSCvr60111

configurations getting wiped off from standby, while deployment fails on active

CSCvr74828

Plaintext passwords logged in asa-appagent.log during bootstrap configuration create/edits

CSCvr79974

Configuration might not replicated if packet loss on the failover Link

CSCvr81457

FTD traceback when TLS tracker (tls_trk_sniff_for_tls) attempted to free a block.

CSCvr85295

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote

CSCvr86077

ASA Traceback/pagefault in Datapath due to re_multi_match_ascii

CSCvr92168

Cisco ASA and Cisco FTD Software OSPF Packets Processing Memory Leak Vulnerability

CSCvs01422

Lina traceback when changing device mode of FTD

CSCvs02954

ASA OSPF: Prefix removed from the RIB when topology changes, then added back when another SPF is run

CSCvs04179

ASA - 9.8.4.12 traceback and reload in ssh or fover_rx Thread

CSCvs05262

Decrement TTL display wrong result

CSCvs15276

ERROR: entry for ::/0 exists when configuring ipv6 icmp