Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 9.12(4)67 – 4/01/2024

Defects resolved since 9.12(4)65

 

CSCwh68482

FTD: Traceback and Reload in Process Name: lina

CSCwi59525

Multiple lina cores on 7.2.6 KP2110 managed by cdFMC

 

CSCwi98284

RCE with disk0: called client_bundle_install.zip that contains a csco_config.lua

CSCwj01344

Remove unused AGG AUTH attributes from code to reduce attack surfaces

CSCwj10955

Cisco ASA and FTD Software Web Services Denial of Service Vulnerability

CSCwj14573

Remove uncalled function ewsStringPrintable()

CSCwi90040

Code Hardening for Backup and Restore to not use Linux Shell Commands.

CSCwi97975

IFS file system directory traversal file system vulnerabilities

 

Revision:  Version 9.12(4)65 – 1/25/2024

Defects resolved since 9.12(4)62:

 

CSCvq48086

ASA concatenates syslog event to other syslog event while sending to the syslog server

CSCwa82736

FTD/ASA: Reordering of AnyConnect image fails with error Unable to remove/install image

CSCwc40352

Lina Netflow sending permited events to Stealthwatch but they are block by snort afterwards

CSCwc78781

ASA/FTD may traceback and reload during ACL changes linked to PBR config

CSCwd28037

TPK: No nameif during traffic causes the device traceback, lina core is generated.

CSCwe28912

FPR 4115- primary unit lost all HA config after ftd HA upgrade

CSCwe87134

ASA/FTD: Traceback and reload due to high rate of SCTP traffic

CSCwe93137

KP - multimode: ASA traceback observed during HA node break and rejoin.

CSCwf36419

ASA/FTD: Traceback and reload with Thread Name 'PTHREAD'

CSCwf47227

Remove Priority-queue command from FTD|| Priority-queue command causes silent egress packet drops

CSCwf60590

show route all summary executed on transparent mode FTD is causing CLISH to become Sluggish.

CSCwf63872

FTD taking longer than expected to form OSPF adjacencies after a failover switchover

CSCwf64590

Units get kicked out of the cluster randomly due to HB miss  | ASA 9.16.3.220

CSCwf69901

FTD: Traceback and reload during OSPF redistribution process execution

CSCwh04395

ASDM application randomly exits/terminates with an alert message on multi-context setup

CSCwh16301

Incorrect Hit count statistics on ASA Cluster only for Cluster-wide output

CSCwh19897

ASA/FTD Cluster: Reuse of TCP Randomized Sequence number on two different conns with same 5 tuple

CSCwh21474

ASA traceback when re-configuring access-list

CSCwh32118

ASDM management-sessions quota reached due to HTTP sessions stuck in CLOSE_WAIT

CSCwh41127

ASA/FTD: NAT64 error "overlaps with inside standby interface address" for Standalone ASA

CSCwh49244

show aaa-server command always shows the Average round trip time 0ms.

CSCwh49483

ASA/FTD may traceback and reload while running show inventory all

CSCwh53745

ASA: unexpected logs for initiating inbound connection for DNS query response

CSCwh59199

ASA/FTD traceback and reload with IPSec VPN, possibly involving upgrade

CSCwh60604

ASA/FTD may traceback and reload in Thread Name 'lina' while processing DAP data

CSCwh65128

LINA show tech-support fails to generate as part of sf_troubleshoot.pl (Troubleshoot file)

CSCwh69346

ASA: Traceback and reload when restore configuration using CLI

CSCwh77747

FPRM Audit logs not generated for user log in

CSCwh95175

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwi02134

FTD sends multiple replicated NetFlow records for the same flow event

CSCwi31091

OSPF Redistribution route-map with prefix-list not working after upgrade

CSCwi40536

ASA/FTD: Traceback and reload when running show tech and under High Memory utilization condition

 

 

Revision:  Version 9.12(4)62 – 11/12/2023

Files:  asa9124-58-smp-k8.bin, cisco-asa-fp2k.9.12.4.58.SPA, cisco-asa.9.12.4.58.SPA.csp

Defects resolved since 9.12(4)58:

 

CSCvt25221

FTD traceback in Thread Name cli_xml_server when deploying QoS policy

CSCwd89095

Stratix5950 and ISA3000 LACP channel member SFP port suspended after reload

CSCwe38029

Multiple traceback seen on standby unit.

CSCwe42061

Deleting a BVI in FTD interfaces is causing packet drops in other BVIs

CSCwe44311

FP2100:Update LINA asa.log files to avoid recursive messages-<date>.1.gz rotated filenames

CSCwe61928

PIM register packets are not sent to RP after a reload if FTD uses a default gateway to reach the RP

CSCwe67816

ASA / FTD Traceback and reload when removing isakmp capture

CSCwe77123

ASA/FTD : Degradation for TCP tput on FPR2100 via IPSEC VPN when there is delay between VPN peers

CSCwe80063

Default DLY value of port-channel sub interface mismatch with parent Portchannel

CSCwe85432

ASA/FTD traceback and reload on thread DATAPATH-14-11344 when SIP inspection is enabled

CSCwe86225

ASA/FTD traceback and reload due citing thread name: cli_xml_server in tm_job_add

CSCwe90720

ASA Traceback and reload in parse thread due ha_msg corruption

CSCwe92905

ngfwManager process continuously restarting leading to ZMQ Out of Memory traceback

CSCwe95757

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwf10910

FTD : Traceback in ZMQ running 7.3.0

CSCwf14126

ASA Traceback and reload citing process name 'lina'

CSCwf14811

TCP normalizer needs stats that show actions like packet drops

CSCwf17042

ASDM replaces custom policy-map with default map on class inspect options at backup restore.

CSCwf20338

ASA may traceback and reload in Thread Name 'DHCPv6 Relay'

CSCwf22005

ASA Packet-tracer displays the first ACL rule always, though matches the right ACL

CSCwf23564

Unable to establish BGP when using MD5 authentication over GRE TUNNEL and FTD as passthrough device

CSCwf26534

ASA/FTD: Connection information in SIP-SDP header remains untranslated with destination static Any

CSCwf33574

ASA access-list entries have the same hash after upgrade

CSCwf33904

[IMS_7_4_0] - Virtual FDM Upgrade fails: HA configStatus='OUT_OF_SYNC after UpgradeOnStandby

CSCwf42144

ASA/FTD may traceback and reload citing process name "lina"

CSCwf44537

99.20.1.16 lina crash on nat_remove_policy_from_np

CSCwf49573

ASA/FTD: Traceback and reload when issuing 'show memory webvpn all objects'

CSCwf54418

Reduce time taken to clear stale IKEv2 SAs formed after Duplicate Detection

CSCwf78321

ASA: Checkheaps traceback and reload due to Clientless WebVPN

CSCwf95147

OSPFv3 Traffic is Centralized in Transparent Mode

CSCwh13821

ASA/FTD may traceback and reload in when changing capture buffer size

CSCwh23567

PAC Key file missing on standby on reload

CSCwe20918

Cisco ASA and FTD Software Remote Access SSL VPN Multiple Certificate Auth Bypass

CSCwf47924

Cisco ASA and FTD VPN Web Client Services Client-Side Request Smuggling Vulnerability

CSCwh23100 

Cisco ASA and FTD Software Remote Access VPN Unauthorized Access Vulnerability

CSCwh45108

Cisco ASA and FTD Software Remote Access VPN Unauthorized Access Vulnerability

CSCwe93561

Cisco ASA and FTD VPN Web Client Services Client-Side Request Smuggling Vulnerability

 

 

Revision:  Version 9.12(4)58 – 05/17/2023

Files:  asa9124-58-smp-k8.bin, cisco-asa-fp2k.9.12.4.58.SPA, cisco-asa.9.12.4.58.SPA.csp

Defects resolved since 9.12(4)56:

 

CSCvv24552

ASA/FTD: Traceback and Reload in Thread Name: Route Table Timestamp Update

CSCvx09860

700-1158: 9 out of 150 VTI sessions down

CSCwa72528

user-name from  certificate  feature does not work with SER option

CSCwd22413

EIGRPv6 - Crashed with "mem_lock: Assertion mem_refcount' failed" on LINA.

CSCwe03529

FTD traceback and reload while deploying PAT POOL

CSCwe07722

Cluster data unit drops non-VPN traffic with ASP reason "VPN reclassify failure

CSCwe20043

256-byte memory block gets depleted on start if jumbo frame is enabled with FTD on ASA5516

CSCwe21187

ASA/FTD may drop multicast packets due to no-mcast-intrf ASP drop reason until UDP timeout expires

CSCwe21280

Multicast connection built or teardown syslog messages may not always be generated

CSCwe29529

FTD MI does not adjust PVID on vlans attached to BVI

CSCwe29850

ASA/FTD Show chunkstat top command implementation

CSCwe36176

ASA/FTD: High failover delay with large number of (sub)interfaces and http server enabled

CSCwe40463

Stale IKEv2 SA formed during simultaneous IKE SA handling when missing delete from the peer

CSCwe44672

Syslog ASA-6-611101 is generated twice for a single ssh connection

CSCwe45779

ASA/FTD drops traffic to BVI if floating conn is not default value due to no valid adjacency

CSCwe51286

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwe59737

ASA/FTD reboots due to traceback pointing to watchdog timeout on p3_tree_lookup

CSCwe61969

ASA Multicontext 'management-only' interface attribute not synced during creation

CSCwe62361

ASA reboots due to heartbeat loss and "Communication with NPU lost"

CSCwe63067

ASA/FTD may traceback and reload in Thread Name 'lina' due to due to tcp intercept stat

CSCwe63232

ASA/FTD: Ensure flow-offload states within cluster are the same

CSCwe64404

ASA/FTD may traceback and reload

CSCwe64563

The command "neighbor x.x.x.x ha-mode graceful-restart" removed when deleting any created context

CSCwe65634

ASA - Standby device may traceback and reload during synchronization of ACL DAP

CSCwe66132

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwe67751

Last fragment from SIP IPv6 packets has MF equal to 1, flagging that more packets are expected

CSCwe74328

AnyConnect - mobile devices are not able to connect when hostscan is enabled

CSCwe78977

ASA/FTD may traceback and reload in Thread Name 'pix_flash_config_thread'

CSCwe79072

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwe80278

Dynamic interface NAT rules cause SSH/ICMP to fail with nat-no-xlate-to-pat-pool in ASA cluster

CSCwe89030

Serial number attribute from the subject DN of certificate should be taken as the username

CSCwe93489

Threat-detection does not recognize exception objects with a prefix in IPv6

CSCwe93532

ASA/FTD may traceback and reload in Thread Name 'lina'.

CSCwf04831

ASA/FTD may traceback and reload in Thread Name 'ci/console'

CSCwe98687

Cisco FTD Software Software for Cisco Firepower 2100 Series Inspection Rules DoS Vulnerability

CSCwd30856

User with no vpn-filter may get additional access when per-user-override is set

CSCwe45093

User with no vpn-filter may get additional access when per-user-override is set (IKEv2 RAVPN)

 

 

Revision:  Version 9.12(4)56 – 03/07/2023

Files:  asa9124-56-smp-k8.bin, cisco-asa-fp2k.9.12.4.56.SPA, cisco-asa.9.12.4.56.SPA.csp

Defects resolved since 9.12(4)55:

 

CSCvy30077

deploying anyconnect group-alias causes breaking HA and ungraceful failover

CSCwb44848

ASA/FTD Traceback and reload in Process Name: lina

CSCwc95290

ESP rule missing in vpn-context may cause IPSec traffic drop

CSCwd04210

ASA: ASDM sessions stuck in CLOSE_WAIT causing lack of MGMT

CSCwd06005

ASA/FTD Cluster Traceback and Reload during node leave

CSCwd23188

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwd33811

Cluster registration is failing because DATA_NODE isn't joining the cluster

CSCwd50218

ASA restore is not applying vlan configuration

CSCwd56296

FTD Lina traceback and reload in Thread Name 'IP Init Thread'

CSCwd56995

Clientless Accessing Web Contents using application/octet-stream vs text/plain

CSCwd63580

FPR2100: Increase in failover convergence time with ASA in Appliance mode

CSCwd63961

AC clients fail to match DAP rules due to attribute value too large

CSCwd66709

FP4125 2.10.1.166 FTD applications in HA went into not responding state

CSCwd69454

Port-channel interfaces of secondary unit are in waiting status after reload

CSCwd74116

S2S Tunnels do not come up due to DH computation failure caused by DSID Leak

CSCwd78624

ASA configured with HA may traceback and reload with multiple input/output error messages

CSCwd82235

LINA Traceback on FPR-1010 under Thread Name: update_cpu_usage

CSCwd84868

Observing some devcmd failures and checkheaps traceback when flow offload is not used.

CSCwd85927

Traceback and reload when webvpn users match DAP access-list with 36k elements

CSCwd91421

ASA/FTD may traceback and reload in logging_cfg processing

CSCwd93376

Clientless VPN users are unable to download large files through the WebVPN portal

CSCwd94096

Anyconnect users unable to connect when ASA using different authentication and authorization server

CSCwd95043

Cisco ASA and FTD VPN Web Client Services Client-Side Request Smuggling Vulnerability

CSCwd95436

Primary ASA traceback upon rebooting the secondary

CSCwd95908

ASA/FTD traceback and reload, Thread Name: rtcli async executor process

CSCwd96755

ASA is unexpected reload when doing backup

CSCwd97020

ASA/FTD: External IDP SAML authentication fails with Bad Request message

CSCwe05913

FTD traceback/reloads - Icmp error packet processing involves snp_nat_xlate_identity

CSCwe14174

FTD - 'show memory top-usage' providing improper value for memory allocation

CSCwe18974

ASA/FTD may traceback and reload in Thread Name: CTM Daemon

CSCwe29583

ASA/FTD may traceback and reload in Thread Name 'None' at lua_getinfo

CSCwd77581

Cisco ASA and FTD ICMPv6 Message Processing Denial of Service Vulnerability

 

Revision:  Version 9.12(4)55 – 12/13/2022

Files:  asa9124-55-smp-k8.bin, cisco-asa-fp2k.9.12.4.55.SPA, cisco-asa.9.12.4.55.SPA.csp

Defects resolved since 9.12(4)54:

 

CSCvz41551

FP2100: ASA/FTD with threat-detection statistics may traceback and reload in Thread Name 'lina'

CSCvz54471

ASA: Failed ASA in HA pair not recovering by itself, after an "HA state progression failed"

CSCvz70958

High Control Plane CPU due to dhcpp_add_ipl_stby

CSCwa04262

Cisco ASA Software SSL VPN Client-Side Request Smuggling Vulnerability 

CSCwa81427

External Authorization randomly fails on ASAv when using LDAP over SSL

CSCwc03507

Constant no-buffer drops on Internal Data interfaces despite little evidence of CPU hog

CSCwc64923

ASA/FTD may traceback and reload in Thread Name 'lina' ip routing ndbshr

CSCwc67687

ASA HA failover triggers HTTP server restart failure and ASDM outage

CSCwc99242

ISA3000 LACP channel member SFP port suspended after reload

CSCwd11855

ASA/FTD may traceback and reload in Thread Name 'ikev2_fo_event'

CSCwd19053

ASA/FTD may traceback with large number of network objects deployment using distribute-list

CSCwd25256

With TCM enabled new ACL's are not working on ASA if non access-group command disabled twice

CSCwd26867

Device should not move to Active state once Reboot is triggered

CSCwd31181

Lina traceback and reload - VPN parent channel (SAL) has an invalid underlying channel

CSCwd38805

Syslog 106016 is not rate-limited by default

CSCwd40260

Serviceability Enhancement - Unable to parse payload are silently drop by ASA/FTD

CSCwd41083

ASA traceback and reload due to DNS inspection

CSCwd48633

ASA - traceback and reload when Webvpn Portal is used

CSCwd49018

After establishing multicontext HA ,SNMP no longer outputs interface information.

CSCwd53135

ASA/FTD: Object Group Search Syslog for flows exceeding threshold

CSCwd56254

show tech-support generation does not include "show inventory" when run on FTD

CSCwd56774

Misleading drop reason in "show asp drop"

CSCwd61016

ASA: Standby may get stuck in "Sync Config" status upon reboot when there is EEM is configured

 

 

Revision:  Version 9.12(4)54 – 10/26/2022

Files:  asa9124-54-smp-k8.bin, cisco-asa-fp2k.9.12.4.54.SPA, cisco-asa.9.12.4.54.SPA.csp

Defects resolved since 9.12(4)52:

 

CSCvs27235

nat-no-xlate-to-pat-pool drops when master leaves cluster and after rebalance

CSCvy65178

Need dedicated Rx rings for to the box BGP traffic on Firepower platform

CSCvy86817

Cruz ASIC CLU filter has the incorrect src/dst IP subnet when a custom CCL IP subnet is set

CSCwb89963

ASA Traceback & reload in thread name: Datapath

CSCwc26648

ASA/FTD Traceback and Reload in Thread name Lina or Datatath

CSCwc36905

ASA  traceback and reload due to "Heap memory corrupted at slib_malloc.c

CSCwc45108

ASA/FTD: GTP inspection causing 9344 sized blocks leak

CSCwc49095

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwc51326

FXOS-based Firepower platform showing 'no buffer' drops despite high values for RX ring watermarks

CSCwc61912

ASA/FTD  OSPFv3 does not generate messages Type 8 LSA for IPv6

CSCwc66757

ASA/FTD may traceback and reload in Thread Name 'lina'

CSCwc72284

TACACS Accounting includes an incorrect IPv6 address of the client

CSCwc73224

Call home configuration on standby device is lost after reload

CSCwc74103

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-11-32591'

CSCwc79366

During the deployment time, device got stuck processing the config request.

CSCwc81960

Unable to configure 'match ip address' under route-map when using object-group in access list

CSCwc88897

ASA traceback and reload due to null pointer in Umbrella after modifying DNS inspection policy

CSCwc90091

ASA 9.12(4)47 with <user-statistics>, will affects the "policy-server xxxx global" visibility.

CSCwc93166

Using write standby in a user context leaves secondary firewall license status in an invalid state

CSCwc94501

ASA/FTD tracebacks due to ctm_n5 resets

CSCwc96805

traceback and reload due to tcp intercept stat in thread unicorn

CSCwd00386

ASA/FTD may traceback and reload when clearing the configration due to "snp_clear_acl_log_flow_all"

CSCwd11303

ASA might generate traceback in ikev2 process and reload

 

 

Revision:  Version 9.12(4)52 – 08/30/2022

Files:  asa9124-52-smp-k8.bin, cisco-asa-fp2k.9.12.4.52.SPA, cisco-asa.9.12.4.52.SPA.csp

Defects resolved since 9.12(4)50:

 

 

CSCvw29647

FTD: NAS-IP-Address:0.0.0.0 in Radius Request packet as network interface for aaa-server not defined

CSCvy96895

ASA disconnects the VTY session using of Active IP address and Standby MAC address after failed over

CSCvz71596

Number of interfaces on Active and Standby are not consistent should trigger warning syslog

CSCvz78816

ASA disconnects the ssh, https session using of Active IP address and Standby MAC address after FO

CSCwa55562

Different CG-NAT port-block allocated for same source IP causing per-host PAT port block exhaustion

CSCwb52401

Cisco Firepower Threat Defense Software Privilege Escalation Vulnerability

CSCwb93914

Cisco ASA Software and FTD Software Web Services Interface Denial of Service Vulnerability

CSCwc02488

ASA/FTD may traceback and reload in Thread Name 'None'

CSCwc03069

Interface internal data0/0 is up/up from cli but up/down from SNMP polling

CSCwc10792

ASA/FTD IPSEC debugs missing reason for change of peer address and timer delete

CSCwc13017

FTD/ASA traceback and reload at at ../inspect/proxy.h:439

CSCwc28532

9344 Block leak due to fragmented GRE traffic over inline-set interface inner-flow processing

CSCwc28806

ASA Traceback and Reload on process name Lina

CSCwc32246

NAT64 translates all IPv6 Address to 0.0.0.0/0 when object subnet 0.0.0.0 0.0.0.0 is used

CSCwc38567

ASA/FTD may traceback and reload while executing SCH code

CSCwc44289

FTD - Traceback and reload when performing IPv4 <> IPv6 NAT translations

CSCwc45397

ASA HA - Restore in primary does not remove new interface configuration done after backup

CSCwc50887

FTD - Traceback and reload on NAT IPv4<>IPv6 for UDP flow redirected over CCL link

CSCwc52351

ASA/FTD Cluster Split Brain due to NAT with "any" and Global IP/range matching broadcast IP

CSCwc53280

ASA parser accepts incomplete network statement under OSPF process and is present in show run

CSCwc54984

IKEv2 rekey - Responding Invalid SPI for the new SPI received right after Create_Child_SA response

CSCwc60037

ASA fails to rekey with IPSEC ERROR: Failed to allocate an outbound hardware context

 

 

Revision:  Version 9.12(4)50 – 08/16/2022

Files:  asa9124-50-smp-k8.bin, cisco-asa-fp2k.9.12.4.50.SPA, cisco-asa.9.12.4.50.SPA.csp

Defects resolved since 9.12(4)48:

 

CSCwb05291

Cisco ASDM and ASA Software Client-side Arbitrary Code Execution Vulnerability

CSCwc64565

ASA Traceback and reload in aaa_shim_thread

 

Revision:  Version 9.12(4)48 – 07/19/2022

Files:  asa9124-48-smp-k8.bin, cisco-asa-fp2k.9.12.4.48.SPA, cisco-asa.9.12.4.48.SPA.csp

Defects resolved since 9.12(4)47:

 

 

CSCvy50598

BGP table not removing connected route when interface goes down

CSCvz31880

ASA Crashing with 'Unicorn Proxy Thread cpu: 9 watchdog_cycles' after stopping scaled stress test.

CSCwa67884

Conditional flow-offload debugging produces no output

CSCwb87950

Cisco ASA Software and FTD Software Web Services Interface Denial of Service Vulnerability

CSCwb08644

ASA/FTD traceback and reload at IKEv2 from Scaled S2S+AC-DTLS+SNMP long duration test

CSCwb17963

Unable to identify dynamic rate liming mechanism & not following msg limit per/sec at syslog server.

CSCwb53328

ASA/FTD Traceback and reload caused by Smart Call Home process sch_dispatch_to_url

CSCwb74571

PBR not working on ASA routed mode with zone-members

CSCwb79812

RIP is advertising all connected Anyconnect users and not matching route-map for redistribution

CSCwb87950

Cisco ASA Software and FTD Software Web Services Interface Denial of Service Vulnerability

CSCwb92709

We can't monitor the interface via "snmpwalk" once interface is removed from context.

CSCwb94190

ASA graceful shut down when applying ACL's with forward reference feature and FIPS enabled.

CSCwb97251

ASA/FTD may traceback and reload in Thread Name 'ssh'

CSCwc09414

ASA/FTD may traceback and reload in Thread Name 'ci/console'

CSCwc11597

ASA tracebacks after SFR was upgraded to 6.7.0.3

CSCwc11663

ASA traceback and reload when modifying DNS inspection policy via CSM or CLI

CSCwc13994

ASA - Restore not remove the  new configuration for an  interface setup after backup

CSCwc18312

show nat pool cluster commands run within EEM scripts lead to traceback and reload

CSCwc23695

ASA/FTD can not parse UPN from SAN field of user's certificate

 

 

Revision:  Version 9.12(4)47 – 06/21/2022

Files:  asa9124-47-smp-k8.bin, cisco-asa-fp2k.9.12.4.47.SPA, cisco-asa.9.12.4.47.SPA.csp

Defects resolved since 9.12(4)41:

 

CSCvu96069

HA during failover active having traffic with high CPU the system may reload unexpected

CSCvw82067

ASA/FTD 9344 blocks depleted due to high volume of fragmented traffic

CSCvy73130

FP4100 platform: Active-Standby changed to dual Active after running "show conn"  command

CSCvz60142

ASA/FTD stops serving SSL connections

CSCvz75988

Inconsistent logging timestamp with RFC5424 enabled

CSCvz85683

Wrong syslog message format for 414004

CSCwa75966

ASA: Reload and Traceback in Thread Name: Unicorn Proxy Thread with Page fault: Address not mapped

CSCwa76564

ASDM session/quota count mismatch in ASA when multiple context switch before and after failover

CSCwb06847

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-9-11543'

CSCwb07908

Standby FTD/ASA sends DNS queries with source IP of 0.0.0.0

CSCwb24039

ASA traceback and reload on routing

CSCwb26212

ASA drops existing anyconnect sessions and stop accepting new ayconnect sessions

CSCwb28849

ASA/FTD: Mitigation of OpenSSL vulnerability CVE-2022-0778

CSCwb51707

ASA Traceback and reload in process name: lina

CSCwb53172

FTD: IKEv2 tunnels flaps every 24 hours and crypto archives are generated

CSCwb57615

Configuring pbr access-list with line number failed.

CSCwb59465

ASA/FTD may traceback (watchdog) and reload when generating a syslog from the VPN Failover subsystem

CSCwb59488

ASA/FTD Traceback in memory allocation failed

CSCwb67040

FP4112|4115 Traceback & reload on Thread Name: netfs_thread_init

CSCwb66761

Cisco Firepower Threat Defense Software Generic Routing Encapsulation DoS Vulnerability

CSCwb68642

ASA traceback in Thread Name: SXP CORE

CSCwb71460

ASA traceback in Thread Name: fover_parse and triggered by snmp related functions

CSCwb74938

ASA traceback and reload with error "assertion "0" failed: file "timer_services.c", line 165"

CSCwb80559

FTD offloads SGT tagged packets although it should not

CSCwb82796

ASA/FTD firewall may traceback and reload when tearing down IKE tunnels

CSCwb83388

ASA HA Active/standby tracebacks seen approximately every two months.

CSCwb87498

Lina traceback and reload during EIGRP route update processing.

CSCwb90074

ASA: Multiple Context Mixed Mode SFR Redirection Validation

CSCwb93932

ASA/FTD traceback and reload with timer services assertion

CSCwb63827 

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DoS

 

 

Revision:  Version 9.12(4)41 – 05/24/2022

Files:  asa9124-41-smp-k8.bin, cisco-asa-fp2k.9.12.4.41.SPA, cisco-asa.9.12.4.41.SPA.csp

Defects resolved since 9.12(4)40:

 

CSCvz09106

Cisco ASA and FTD Software SSL VPN Denial of Service Vulnerability

 

 

Revision:  Version 9.12(4)40 – 04/20/2022

Files:  asa9124-40-smp-k8.bin, cisco-asa-fp2k.9.12.4.40.SPA, cisco-asa.9.12.4.40.SPA.csp

Defects resolved since 9.12(4)39:

 

CSCwa26535

IPv6 PMTU discovery does not work for RA VPN Cllient with tunneled route

CSCwa41936

Cisco FTD Bleichenbacher Attack Vulnerability

CSCwa61361

ASAv traceback when SD_WAN ACL enabled, then disabled (or vice-versa) in PBR

CSCwa73172

ASA reload and traceback in Thread Name: PIX Garbage Collector

CSCvz98540

Cisco ASA and FTD Software SSL/TLS Client Denial of Service Vulnerability

CSCwa85043

Traceback: Lina traceback and reload on thread name: Logger

CSCwa87597

ASA/FTD Failover: Joining Standby reboots when receiving configuration replication from Active mate

CSCwa96759

Lina may traceback and reload on tcpmod_proxy_handle_mixed_mode

CSCwb07981

Traceback: Standby FTD reboots and generates crashinfo and lina core on thread name cli_xml_server

CSCwb11939

ASA/FTD MAC modification is seen in handling fragmented packets with INSPECT on

CSCwb18252

FTD/ASA: Traceback on BFD function causing unexpected reboot

CSCwb25809

Single Pass - Traceback due to stale ifc

 

 

Revision:  Version 9.12(4)39 – 03/17/2022

Files:  asa9124-39-smp-k8.bin, cisco-asa-fp2k.9.12.4.39.SPA, cisco-asa.9.12.4.39.SPA.csp

Defects resolved since 9.12(4)38:

 

CSCvw62288

ASA: 256 bytes block depletion when syslog rate is high

CSCvy04430

Management Sessions fail to connect after several weeks

CSCvz71064

Deleting The Context from ASA taking Almost 2 Minutes with ikev2 tunnel

CSCwa06960

ASA Traceback and Reload due to CTM daemon during internal health test

CSCwa44950

ASA/FTD - Memory leak observed when VPN is deployed

CSCwa56449

ASA traceback in HTTP cli EXEC  code

CSCwa56975

DHCP Offer not seen on control plane

CSCwa57115

New access-list are not taking effect after removing non-existance ACL with objects.

CSCwa60574

Coverity 859475: CONSTANT_EXPRESSION_RESULT in snp_ha_trans_tear_down_ch

CSCwa61218

Polling OID "1.3.6.1.4.1.9.9.171.1.3.2.1.2" gives negative index value of the associated tunnel

CSCwa65389

ASA traceback and reload in Unicorn Admin Handler when change interface configuration via ASDM

CSCwa67882

Offloaded GRE tunnels may be silently un-offloaded and punted back to CPU

CSCwa68660

FTP inspection stops working properly after upgrading the ASA to 9.12.4.x

CSCwa74900

Traceback and reload after enabling debug webvpn cifs 255

CSCwa79494

Traffic keeps failing on Hub when IPSec tunnel from Spoke flaps

CSCwa85138

Multiple issues with transactional commit diagnostics

CSCwa87315

ASA/FTD may traceback and reload in Thread Name 'IP Address Assign'

CSCwa94894

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-4-9608'

CSCwa97784

ASA: Jumbo sized packets are not fragmented over the L2TP tunnel

CSCwb01700

ASA: SSH and ASDM sessions stuck in CLOSE_WAIT causing lack of MGMT for the ASA

CSCwb01919

FP2140 ASA 9.16.2 HA units traceback and reload at lua_getinfo (getfuncname)

 

 

Revision:  Version 9.12(4)38 – 02/09/2022

Files:  asa9124-38-smp-k8.bin, cisco-asa-fp2k.9.12.4.38.SPA, cisco-asa.9.12.4.38.SPA.csp

Defects resolved since 9.12(4)37:

 

CSCvt67167

Data Unit traceback and reload without traffic at Thread Name :"logger"

CSCvw02334

ipv6 route table ( data and management ) in a multi-context environment.

CSCvx24245

ASA Traceback and reload in occam_group_free

CSCvx78968

ASA/FTD Traceback and reload on Thread Name: IKEv2 Daemon with VTIs configured

CSCvx97053

Unable to configure ipv6 address/prefix to same interface and network in different context

CSCvy04343

ASA in PLR mode,"license smart reservation" is failing.

CSCvz05541

ASA55XX: Expansion module interfaces not coming up after a software upgrade

CSCvz08387

ASP drop capture output may display incorrect drop reason

CSCvz33468

Nat hitcount not updated in FQDN_NAT

CSCvz44645

FTD may traceback and reload in Thread Name 'lina'

CSCvz68336

SSL decryption not working due to single connection on multiple in-line pairs

CSCvz73146

FTD - Traceback in Thread Name: DATAPATH

CSCvz76746

While implementing management tunnel a user can use open connect to bypass anyconnect.

CSCvz76966

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DNS DoS

CSCvz86256

Primary ASA should send GARP as soon as split-brain is detected and peer becomes cold standby

CSCvz89126

ASDM session/quota count mismatch in ASA when multiple context switchover is done from ASDM

CSCvz89327

OSPFv2 flow missing cluster centralized "c" flag

CSCvz91218

Statelink hello messages dropped on Standby unit due to interface ring drops on high rate traffic

CSCvz92016

ASA Privilege Escalation with valid user in AD

CSCvz92932

ASA show tech execution causing spike on CPU and impacting to IKEv2 sessions

CSCvz95108

FTD Deployment failure post upgrade due to major version change on device

CSCwa08262

AnyConnect users with mapped group-policies take attributes from default GP under the tunnel-group

CSCwa13873

ASA Failover Split Brain caused by delay on state transition after "failover active" command run

CSCwa14485

Cisco Firepower Threat Defense Software Denial of Service Vulnerability

CSCwa15185

ASA/FTD: remove unwanted process call from LUA

CSCwa18858

ASA drops non DNS traffic with reason "label length 164 bytes exceeds protocol limit of 63 bytes"

CSCwa19443

Flow Offload - Compare state values remains in error state for longer periods

CSCwa28822

FTD moving UI management from FDM to FMC causes traffic to fail

CSCwa30114

Error:NAT unable to reserve ports when using a range of ports in an object service

CSCwa36535

Standby unit failed to join failover due to large config size.

CSCwa33898

Cisco Adaptive Security Appliance Software Clientless SSL VPN Heap Overflow Vulnerability

CSCwa40719

Traceback: Secondary firewall reloading in Threadname: fover_parse

CSCwa41834

ASA/FTD traceback and reload due to  pix_startup_thread

CSCwa47041

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DAP DoS

 

CSCwa53489

Lina Traceback and Reload Due to invalid memory access while accessing Hash Table

 

CSCwa55878

FTD Service Module Failure: False alarm of "ND may have gone down"

 

CSCwa58686

ASA/FTD Change in OGS compilation behavior causing boot loop

 

 

 

Revision:  Version 9.12(4)37 – 11/18/2021

Files:  asa9124-37-smp-k8.bin, cisco-asa-fp2k.9.12.4.37.SPA, cisco-asa.9.12.4.37.SPA.csp

Defects resolved since 9.12(4)35:

 

CSCvq54299

After restart of both A/S units, not all context configs may be loaded when using SL on 2100

CSCvu08773

R291 : Blade reboots continuously on doing backward compatibility testing with 9.8.4

CSCvu97242

2100: Corefile and crashinfo might both be truncated and incomplete in the event of a crash

CSCvv07917

ASA learning a new route removes asp route table created by floating static

CSCvv55248

Syslogs generated for ACL transaction commit are not in consistent format & not available some times

CSCvy35737

FTD traceback and reload during anyconnect package verification

CSCvy96325

FTD/ASA: Adding new ACE entries to ACP causes removal and re-add of ACE elements in LINA

CSCvz20679

FTDv - Lina Traceback and reload

CSCvz39565

ASA/FTD Traceback and Reload during bulk VPN session connect

CSCvz40352

ASA traffic dropped by Implicit ACL despite the fact of explicit rules present on Access-list

CSCvz58710

ASA traceback due to SCTP traffic.

CSCvz60901

ASA: IPv6 Neighbor reachability issues

CSCvz62379

Cisco ASA and FTD Software Dynamic Access Policies Denial of Service Vulnerability

CSCvz64470

ASA/FTD Traceback and reload due to memory corruption when generating ICMP unreachable message

CSCvz66795

ASA traceback and reload in SSH process when executing the command "show access-list"

CSCvz77744

OSPFv3: FTD Wrong "Forwarding address" added in ospfv3 database

CSCvz84850

ASA/FTD traceback and reload caused by "timer services" function

CSCvz87824

ASASM traceback and reload on "snp_svcmod_heart_beat_timeout_cb" function

CSCvz89545

SSL VPN performance degraded and significant stability issues after upgrade

CSCwa03275

BGP routes shows unresolved and dropping packet with asp-drop reason "No route to host"

CSCwa03347

IPv6 PIM packets are dropped in ASP with invalid-ip-length drop reason

CSCwa04461

Cisco ASA Software and FTD Software Remote Access SSL VPN Denial of Service

 

 

Revision:  Version 9.12(4)35 – 10/12/2021

Files:  asa9124-35-smp-k8.bin, cisco-asa-fp2k.9.12.4.35.SPA, cisco-asa.9.12.4.35.SPA.csp

Defects resolved since 9.12(4)30:

 

CSCvq43454

ENH: Support a tolerance time for the "NotValidBefore" timestamp, while using SAML auth

CSCvs27336

Traceback on ASA by Smart Call Home process

CSCvu36302

%ASA-3-737403 is used incorrectly when vpn-addr-assign local reuse-delay is configured

CSCvv48594

Memory leak: due to snp_tcp_intercept_stat_top_n_integrate() in threat detection

CSCvy21334

Active tries to send CoA update to Standby in case of "No Switchover"

CSCvy39621

ASA/FTD sends continuous Radius Access Requests Even After Max Retry Count is Reached

CSCvz07614

ASA: Orphaned SSH session not allowing us to delete a policy-map from CLI

CSCvz21886

Twice nat's un-nat not happening if nat matches a pbr acl that matches a port number instead of IP

CSCvz29233

ASA: ARP entries from custom context not removed when an interface flap occurs on system context

CSCvz34831

If ASA fails to download DACL it will never stop trying

CSCvz38361

BGP packets dropped for non directly connected neighbors

CSCvz70595

Traceback observed on ASA while handling SAML handler

 

 

Revision:  Version 9.12(4)30 – 08/24/2021

Files:  asa9124-30-smp-k8.bin, cisco-asa-fp2k.9.12.4.30.SPA, cisco-asa.9.12.4.30.SPA.csp

Defects resolved since 9.12(4)26:

 

CSCvr33428

FMC generates Connection Events from a SYN flood attack

CSCvt15348

ASA show processes cpu-usage output is misleading on multi-core platforms

CSCvv43190

Crypto engine errors when GRE header protocol field doesn't match protocol field in inner ip header

CSCvv48942

Snmpwalk showing traffic counter as 0 for failover interface

CSCvx50980

ASA CP CPU wrong calculation leads to high percentage (100% CP CPU)

CSCvx64478

Unwanted console output during SAML transactions

CSCvx80830

VPN conn fails from same user if Radius server sends a dACL and vpn-simultaneous-logins is set to 1

CSCvy12782

FTD/ASA: PATed traffic impacted when configured on ixgbe-vf SRIOV interfaces in HA

CSCvy33676

UN-NAT created on FTD once a prior dynamic xlate is created

CSCvy47108

Remote Access IKEv2 VPN session cannot be established because of stuck Uauth entry

CSCvy61008

Time out of sync between Lina and FXOS

CSCvy64911

SNMP MIB value for crasLocalAddress is not showing the IP address

CSCvy74781

The standby device is sending the keep alive messages for ssl traffic after the failover

CSCvy96625

Revert 'fix' introduced by CSCvr33428 and CSCvy39659

CSCvz00383

FTD lina traceback and reload in thread Name Checkheaps

CSCvz05189

FTD reload with Lina traceback during xlate replication in Cluster

CSCvz15529

ASA traceback and reload thread name: Datapath

CSCvz20544

ASA/FTD may traceback and reload in loop processing Anyconnect profile

CSCvz25434

ASA/FTD blackholes traffic due to 1550 block depletion when BVI is configured as DHCP client

 

 

Revision:  Version 9.12(4)29 – 07/27/2021

Files:  asa9124-29-smp-k8.bin, cisco-asa-fp2k.9.12.4.29.SPA, cisco-asa.9.12.4.29.SPA.csp

Defects resolved since 9.12(4)26:

 

CSCum03297

ENH: ASA should save the timestamp of the MAXHOG in 'show proc cpu-hog'

CSCvr11958

AWS FTD: Deployment failure with ERROR: failed to set interface to promiscuous mode

CSCvu30704

ASA traceback with crashinfo of size "0"

CSCvw71405

FPR1120 running ASA traceback and reload in crypto process.

CSCvy17470

ASA Traceback and reload on the A/S failover pair at IKEv2.

CSCvy43447

FTD traceback and reload on Lic TMR Thread on Multi Instance FTD

CSCvy48159

ASA Traceback & reload on process name lina due to memory header validation

CSCvy49732

ASA/FTD may traceback and reload in Thread Name 'ssh'

CSCvy50011

ASA traceback in IKE Daemon process and  reload

CSCvy51814

Firepower flow-offload stops offloading all existing and new flows

CSCvy52074

ASA/FTD may traceback and reload in Thread Name 'webvpn_task'

CSCvy53461

RSA keys & Certs get removed post reload on WS-SVC-ASA-SM1-K7 with ASA code 9.12.x

CSCvy64492

ASAv adding non-identity L2 entries for own addresses on MAC table and dropping HA hellos

CSCvy69189

FTD HA stuck in bulk state due to stuck vpnfol_sync/Bulk-sync keytab

CSCvy72846

ASA accounting reports incorrect Acct-Session-Time

CSCvy92990

FTD traceback and reload related to SSL after upgrade to 7.0

CSCvz00699

Traceback in webvpn and reload experienced periodically after ASA upgrade

 

 

Revision:  Version 9.12(4)26 – 06/22/2021

Files:  asa9124-26-smp-k8.bin, cisco-asa-fp2k.9.12.4.26.SPA, cisco-asa.9.12.4.26.SPA.csp

Defects resolved since 9.12(4)24:

 

CSCuz67596

ASA may Traceback with Thread Name: Unicorn Admin Handler

CSCvg66052

2 CPU Cores continuously spike on firepower appliances

CSCvv71097

traceback: ASA reloaded snp_fdb_destroy_fh_callback+104

CSCvw03628

ASA will not import CA certificate with name constraint of RFC822Name set as empty

CSCvw62526

ASA traceback and reload on engineering ASA build - 9.12.3.237

CSCvx23833

IKEv2 rekey - Invalid SPI for ESP packet using new SPI received right after Create_Child_SA response

CSCvx24537

SAML: SAML Authentication may fail if we have 2 or more IDP certs with same Subject Name

CSCvx77768

Traceback and reload due to Umbrella

CSCvx87709

FPR 2100 running ASA in HA.  Traceback and reload on watchdog during failover

CSCvx97632

ASA traceback and reload when copying files with long destination filenames using cluster command

CSCvy01752

Traceback on FPR 4115 in Thread - Lic HA Cluster

CSCvy03006

improve debugging capability for uauth

CSCvy04869

AnyConnect certificate authentication fails if user certificate has 8192 bits key size

CSCvy07491

ASA traceback when re-configuring access-list

CSCvy08908

Port-forwarding application blocked by Java

CSCvy10583

ASA Traceback and Reload in Thread Name: DATAPATH

CSCvy16179

ASA cluster Traceback with Thread Name: Unicorn Admin Handler even when running fix for CSCuz67596

CSCvy17078

Traceback: ASA on FPR 2110 traceback and reload on process Lina

CSCvy17365

REST API Login Page Issue

CSCvy23349

FTD unnecessarily ACKing TCP flows on inline-pair deployment

CSCvy25849

ASA fails to process the OCSP response when the string 'OK' is missing in the HTTP response

CSCvy33105

Ambiguous command error is shown for 'show route bgp' or 'show route isis' if DNS lookup is enabled

CSCvy39659

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-15-14815'

 

 

Revision:  Version 9.12(4)24 – 05/11/2021

Files:  asa9124-24-smp-k8.bin, cisco-asa-fp2k.9.12.4.24.SPA, cisco-asa.9.12.4.24.SPA.csp

Defects resolved since 9.12(4)18:

 

CSCvm76755

DP-CP arp-in and adj-absent queues need to be separated

CSCvp69936

ASA Traceback on tcp_intercept Thread name : Threat detection

CSCvt10944

ctm crashed while sending emix traffic over VTI tunnel

CSCvv85029

ASA5555 traceback and reload on Thread Name: ace_work

CSCvw06298

ASA duplicate MAC addresses in Shared Interfaces of different Contexts causing traffic impact

CSCvw18614

ASA traceback in the LINA process

CSCvw42091

FTD/HA: "no shutdown" command disappear from running-config of standby

CSCvw71766

ASA traceback and reload in Thread: Ikev2 Daemon

CSCvx04003

Lack of throttling of ARP miss indications to CP leads to oversubscription

CSCvx17664

ASA may traceback and reload in Thread Name 'webvpn_task'

CSCvx25719

X-Frame-Options header is not set in webvpn response pages

CSCvx29771

Firewall CPU can increase after a bulk routing update with flow offload

CSCvx29814

IP address in DHCP GIADDR field is reversed after sending DHCP DECLINE to DHCP server

CSCvx29832

CPU performance degrade with lots of route updates with flow offload enabled

CSCvx34237

ASA reload with FIPS failure

CSCvx42081

FPR4150 ASA Standby Ready unit Loops to failed and remove config to install it again

CSCvx45976

ASA/FTD Watchdog forced traceback and reload in Thread name: vnet-proxy (rip: socks_proxy_datarelay)

CSCvx47230

X-Frame-Options header support for older versions of IE and windows platforms

CSCvx54235

ASP capture dispatch-queue-limit shows no packets

CSCvx57417

Smart Tunnel Code signing certificate renewal

CSCvx65745

FPR2100: enable kernel panic on octeon for UE events to trigger crash

CSCvx68355

ASA - unable to import CA certificate when countryName is encoded as UTF8

CSCvx71434

ASA/FTD Traceback and reload in Thread Name: pix_startup_thread due to asa_run_ttyS0 script

CSCvx71571

ASA: "ERROR: Unable to delete entries from Hash Table" with CSM

CSCvx73164

Lasso SAML Implementation Vulnerability Affecting Cisco Products: June 2021

CSCvx75963

ASA traceback while taking captures

CSCvx86621

ASA(lina) clock (always shows Jan 2010) does not sync properly with fxos

CSCvx95255

Supportive change in ASA to differentiate, new ASDM connections from existing ASDM context switch

CSCvy02703

ASA/FTD tracebacks due to CTM message handler

CSCvy08908

Port-forwarding application blocked by Java

 

 

Revision:  Version 9.12(4)18 – 03/31/2021

Files:  asa9124-18-smp-k8.bin, cisco-asa-fp2k.9.12.4.18.SPA, cisco-asa.9.12.4.18.SPA.csp

Defects resolved since 9.12(4)13:

 

CSCvc07112

Implement detection and auto-fix capability for scheduler corruption problems

CSCvt54182

LINA cores are generated when FTD is configured to do SSL decryption.

CSCvt93142

ASA should allow null sequence encoding in certificates for client authentication.

CSCvv31629

Intermittently embedded ping reply over GRE drops on FTD cluster if traffic passes asymmetrically.

CSCvv97877

Secondary unit not able to join the cluster

CSCvw23199

ASA/FTD Traceback and reload in Thread Name: Logger

CSCvw51950

FPR 4K: SSL trust-point removed from new active ASA after manual Failover

CSCvw60177

Standby/Secondary cluster unit might crash in Thread Name: fover_parse and "cluster config sync"

CSCvw82629

ASA Tracebacks when making "configuration session" changes regarding an ACL.

CSCvw95301

ASA traceback and reload with Thread name: ssh when capture was removed

CSCvw96488

Traceback in inspect_h323_ras+1810

CSCvx02869

Traceback in Thread Name: Lic TMR

CSCvx04057

When SGT name is unresolved and used in ACE, line is not being ignored/inactive

CSCvx04643

ASA reload is removing 'content-security-policy' config

CSCvx08734

ASA: default IPv6/IPv4 route tunneled does not work

CSCvx11460

Firepower 2110 silently dropping traffic with TFC enabled on the remote end

CSCvx13694

ASA/FTD traceback in Thread Name: PTHREAD-4432

CSCvx15040

DHCP Proxy Offer is getting drop on the ASA/FTD

CSCvx20352

Snort PDTS buffer corruption during upgrade or heavy traffic load

CSCvx21782

Firepower platforms generate corrupted coredump due to lina monitor

CSCvx26808

FTD traceback and reload on process lina on FPR2100 series

CSCvx27430

ASA: Unable to import PAC file if FIPS is enabled.

CSCvx30314

ASA 9.15.1.7 traceback and reload in  Thread Name: DATAPATH

CSCvx41171

Concurrent modification of ACL configuration breaks output of "show running-config" completely

CSCvx42197

ASA EIGRP route stuck after neighbour disconnected

CSCvx44401

FTD/ASA traceback in Thread Name : Unicorn Proxy Thread

CSCvx48490

SSL Decrypted https flow EOF events showing 'Initiator/Responder' Packets as 0

CSCvx50366

Traceback in Thread Name: fover_health_monitoring_thread

CSCvx52122

ASA traceback and reload in SNMP Notify Thread while deleting transparent context

CSCvx59120

COA Received before data tunnel comes up results in tear down of parent session

 

 

Revision:  Version 9.12(4)13 – 02/16/2021

Files:  asa9124-13-smp-k8.bin, cisco-asa-fp2k.9.12.4.13.SPA, cisco-asa.9.12.4.13.SPA.csp

Defects resolved since 9.12(4)10:

 

CSCvg69380

ASA - rare cp processing corruption causes console lock

CSCvm82290

ASA core blocks depleted when host unreachable in IRB/TFW configuration

CSCvp63814

FTD - Inner Flow: Carrier id flow lookup enhancement

CSCvq49124

ASA on FP1010 Traceback in http_exec_cli thread

CSCvs13204

ASAv failover traffic on SR-IOV interfaces might be dropped due to interface-down

CSCvs72450

FXOS - Recover hwclock of service module from corruption due to simultaneous write collision

CSCvs84542

ASA traceback with thread: idfw_proc

CSCvu55469

FTD - Connection idle timeout doesn't reset

CSCvu98222

FTD Lina engine may traceback in datapath after enabling SSL decryption policy

CSCvv16082

stress/low memory: assert: mh->mh_mem_pool > MEMPOOL_UNDEFINED && mh->mh_mem_pool < MEMPOOL_MAX_TYPE

CSCvv19230

ASAv Anyconnect users unexpectedly disconnect with reason: Idle Timeout

CSCvv70984

ASA traceback while modifying the bookmark SSL Ciphers configuration

CSCvv87232

ASA: High number of CPU hog in igb_saleen_io_sfp_mod_poll_thread process

CSCvw12100

ASA stale VPN Context seen for site to site and AnyConnect sessions

CSCvw22881

radius_rcv_auth can shoot up control plane CPU to 100%.

CSCvw24556

TCP File transfer (Big File) not properly closed when Flow offload is enabled

CSCvw26331

ASA traceback and reload on Thread Name: ci/console

CSCvw31569

Director/Backup flows are left behind and traffic related to this flow is blackholed

CSCvw33987

ASAv/2100 Smart License failure post upgrade

CSCvw36662

TACACS+ ASCII password change request not handled properly

CSCvw37259

VPN syslogs are generated at a rate of 600/s until device goes into a hang state

CSCvw43486

ASA/FTD Traceback and reload during PBR configuration change

CSCvw44122

ASA: "class-default" class-map redirecting non-DNS traffic to DNS inspection engine

CSCvw47321

IPSec transport mode traffic corruption for inbound traffic for some FPR platforms

CSCvw48517

DAP stopped working after upgrading the ASA to 9.13(1)13

CSCvw51462

IPv4 Default Tunneled Route Rejected

CSCvw51985

ASA: AnyConnect sessions cannot be resumed due to ipv6 DACL failure

CSCvw53255

FTD/ASA HA: Standby Unit FXOS is still able to forward traffic even after failover due to traceback

CSCvw53427

ASA Fails to process HTTP POST with SAML assertion containing multiple query parameters

CSCvw54640

FPR-4150 - ASA traceback and reload with thread name DATAPATH

CSCvw54802

Revocation check fails to move to none after ocsp check fails due to server being unavailable

CSCvw58414

Name of anyconnect custom attribute of type dynamic-split-exclude-domains is changed after reload

CSCvw59035

Connection issues to directly connected IP from FTD BVI address

CSCvw63862

ASA: Random L2TP users cannot access resources due to stale ACL filter entries

CSCvw74940

ASA traceback in IKE Daemon and reload

CSCvw81897

ASA: OpenSSL Vulnerability CVE-2020-1971

CSCvw83572

BVI HTTP/SSH access is not working in versions 9.14.1.30 or above

CSCvw84339

Managed device backup fails, for FTD, if hostname exceeds 30 characters

CSCvw87788

ASA traceback and reload webvpn thread

CSCvw89365

ASA/FTD may traceback and reload during certificate changes

CSCvw97821

ASA: VPN traffic does not pass if no dACL is provided in CoA

CSCvw98840

ASA: dACL with no IPv6 entries is not applied to v6 traffic after CoA

CSCvx01805

AppAgent gets deregistered due to hearbeat failure during config sync up on Firepower 2100s

CSCvx03764

Offload rewrite data needs to be fixed for identity nat traffic and clustering environment

CSCvx11295

ASA may traceback and reload on thread Crypto CA

 

 

Revision:  Version 9.12(4)10 – 12/01/2020

Files:  asa9124-10-smp-k8.bin, cisco-asa-fp2k.9.12.4.10.SPA, cisco-asa.9.12.4.10.SPA.csp

Defects resolved since 9.12(4)7:

 

CSCvg73237

ENH: Configure CAC as an absolute value as well instead of just percentage of total VPN capacity.

CSCvn16864

ENH: Missing Content-Security-Policy Header in ASA HTTP WebVPN portal

CSCvn16887

ENH: Missing X-XSS-Protection Header in ASA HTTP WebVPN portal

CSCvo34210

ASA running 9.6.4.20 Traceback in threadname Unicorn Proxy Thread

CSCvp13352

ASA continues to do TCP keepalives for Client side connections even after vpn session times out

CSCvq98396

ASA: crypto session handles leak on the standby unit

CSCvt71529

ASA traceback and reload during SSL handshake

CSCvt75760

Traceback/Page-fault in Clientless WebVPN due to HTTP cleanup

CSCvt83133

Unable to access anyconnect webvpn portal from google chrome using group-url

CSCvt99137

With huge FTP traffic in cluster, the SEC_FLOW messages are in a retransmit loop

CSCvu42379

High LINA CPU due to flow offload

CSCvu66332

Lina traceback when FTD is configured with passive interface in HA with span traffic on it.

CSCvv15572

ASA traceback observed when "config-url" is entered while creating new context

CSCvv58332

ASA/FTD is reading BGP MP_REACH_NLRI attribute's next-hop bytes in reverse order

CSCvv66005

ASA traceback and reload on inspect esmtp

CSCvv67500

ASA 9.12 random traceback and reload in DATAPATH

CSCvv72466

OSPF network commands go missing in the startup-config after upgrading the ASA

CSCvv73017

Traceback due to fover and ssh thread

CSCvv86926

Unexpected traceback and reload on FTD creating a Core file

CSCvv90181

No deployment failure reason in transcript if 'show running-config' is running during deployment

CSCvv90720

Mac address-table is flapping on 3850 when ASA etherchannel is configued with active mode

CSCvv94701

ASA keeps reloading with "octnic_hm_thread". After the reload, it takes very long time to recover.

CSCvw05393

Certificate validation syslog is not generated on OCSP revocation check

CSCvw06195

ASA traceback cp_midpath_process_thread

CSCvw07000

Snort busy drops with PDTS Tx queue stuck

CSCvw12008

ASA traceback and reload while executing "show tech-support" command

CSCvw21844

FTD traceback and reload on DATAPATH thread when processing encapsulated flows

CSCvw22986

Secondary unit stuck in Bulk sync infinitely due to interface of Primary stuck in init state

CSCvw26171

ASA syslog traceback while strncpy NULL string passed from SSL library

CSCvw27301

IKEv2 with EAP, MOBIKE status fails to be processed.

CSCvw32518

ASASM traceback and reload after upgrade up to 9.12(4)4 and higher

CSCvw42999

9.10.1.11 ASA on FPR2110 traceback and reloads randomly

 

 

Revision:  Version 9.12(4)7 – 10/21/2020

Files:  asa9124-7-smp-k8.bin, cisco-asa-fp2k.9.12.4.7.SPA, cisco-asa.9.12.4.7.SPA.csp

Defects resolved since 9.12(4)4:

 

CSCvf88062

CTM: Nitrox S/G lengths need to be validated

CSCvg69380

ASA - rare cp processing corruption causes console lock

CSCvn16877

ENH: Missing X-Content-Type-Options Header in ASA HTTP WebVPN portal

CSCvq47743

AnyConnect and Management Sessions fail to connect after several weeks

CSCvu06767

Lina cores on multi-instance causing a boot loop on both logical-devices

CSCvu29660

Block exhaustion snapshot not created when available blocks goes to zero

CSCvu33992

traceback: ASA reloaded lina_sigcrash+1394

CSCvu43355

FTD Lina traceback in datapath due to double free

CSCvu68529

Embryonic connections limit does not work consistently

CSCvu70931

Cluster / aaa-server key missing after "no key config-key" is entered

CSCvu89110

ASA: Block new conns even when the "logging permit-hostdown" is set & TCP syslog is down

CSCvv10778

Traceback in threadname DATAPATH (5585) or Lina (2100) after upgrade to 9.12.4

CSCvv23370

Observed traceback in FPR2130 while running webVPN, SNMP related traffic.

CSCvv25394

After upgrade ASA swapped names for disks, disk0 became disk1 and vice versa.

CSCvv32333

ASA still doesn't allow to poll internal-data0/0 counters via SNMP in multiple mode

CSCvv36725

ASA logging rate-limit 1 5 message ... limits to 1 message in 10 seconds instead of 5

CSCvv37629

Malformed SIP packets leads to 4k block hold-up till SIP conn timeout causing probable traffic issue

CSCvv40223

Error parsing flash:/LOCAL-CA-SERVER/LOCAL-CA-SERVER.cdb, when trying to modify/read the user-db

CSCvv41453

Removing static ipv6 route from management-only route table affects data traffic

CSCvv43484

ASA stops processing RIP packets after system upgrade

CSCvv44270

ASAv5 reloads without traceback.

CSCvv48942

Snmpwalk showing traffic counter as 0 for failover interface

CSCvv49698

ASA Anyconnect url-redirect not working for ipv6

CSCvv49800

ASA/FTD: HA switchover doesn't happen with graceful reboot of firepower chassis

CSCvv50107

FTD Traceback and reload while trying to switch peer on HA

CSCvv50338

Traceback Cluster unit on snpi_nat_xlate_destroy+2508

CSCvv52591

DMA memory leak in ctm_hw_malloc_from_pool causing management and VPN connections to fail

CSCvv53696

ASA/FTD traceback and reload during AAA or CoA task of Anyconnect user

CSCvv57842

WebSSL clientless user accounts being locked out on 1st bad password

CSCvv58605

ASA traceback and reload in thread:Crypto CA,mem corruption by unvirtualized pki global table in MTX

CSCvv62305

ASA traceback and reload in fover_parse when attempting to join the failover pair.

CSCvv63412

ASA dropping all traffic with reason "No route to host" when tmatch compilation is ongoing

CSCvv66920

Inner flow: U-turn GRE flows trigger incorrect connection flow creation

CSCvv87496

ASA cluster members 2048 block depletion due to "VPN packet redirect on peer"

CSCvv88017

ASA: EasyVPN HW Client triggers duplicate phase 2 rekey causing disconnections across the tunnel

 

 

Revision:  Version 9.12(4)4 – 09/09/2020

Files:  asa9124-4-smp-k8.bin, cisco-asa-fp2k.9.12.4.4.SPA, cisco-asa.9.12.4.4.SPA.csp

Defects resolved since 9.12(4)2:

 

CSCuw51499

TCM doesn't work for ACE addition/removal, ACL object/object-group edits

CSCvh19161

ASA/FTD traceback and reload in Thread Name: SXP CORE

CSCvk51778

show inventory (or) "show environment" on ASA 5515/5525/5545/5555 shows up Driver/ioctl error logs

CSCvm98585

CPU hog from idfw module observed in 5525 FTD

CSCvn12453

Implement debug menu command to show RX ring number a flow is hashed to

CSCvq43920

Cisco Firepower Threat Defense Software Hidden Commands Vulnerability

CSCvq51284

FPR 2100, low block  9472 causes packet loss through the device.

CSCvr35872

ASA traceback Thread Name: DATAPATH with PBR configured

CSCvr90462

Improve ipv6 duplicate address detection to avoid disabling ipv6 in case of transient active-active

CSCvr99222

NTP configuration is not synchronized to LINA on Multi Instance

CSCvs31112

Unexpected ASA reload and/or truncated crashinfo when issuing 'crashinfo force'

CSCvs56888

Cisco Firepower Threat Defense Software TCP Flood Denial of Service Vulnerability

CSCvt11302

On FPR devices when FIPS is enabled cannot create webtype ACLs

CSCvt35897

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DoS Vuln

CSCvt50528

Warning Message for default settings with Installation of Certificates in ASA/FTD - CLI

CSCvu05180

aaa-server configuration missing on the FTD after a Remote Access VPN policy deployment

CSCvu16423

ASA 9.12(2) - Multiple tracebacks due to Unicorn Proxy Thread

CSCvu29395

Traceback observed while performing master role change with active IGMP joins

CSCvu45822

ASA experienced a traceback and reloaded

CSCvu46685

Cisco ASA and FTD Software SSL/TLS Session Denial of Service Vulnerability

CSCvu47925

Cisco ASA and FTD IP Fragment Memory Leak Vulnerability

CSCvu48285

ASA configured with TACACS REST API: /cli api fail with "Command authorization failed" message

CSCvu59817

Cisco ASA and FTD Software SSL VPN Direct Memory Access Denial of Service Vulnerability

CSCvu61704

ASA high CPU with intel_82576_check_link_thread impacting on overall unit performance

CSCvu63458

FPR2100: Show crash output on show tech does not display outputs from most recent tracebacks

CSCvu75615

Cisco ASA Software and FTD Software WebVPN Portal Access Rule Bypass Vulnerability

CSCvu78721

Cannot change (modify) interface speed after upgrade

CSCvu91792

SNMP IfInDiscards OIDs for Internal-Data 0/0 and 0/1 may return incorrect values

CSCvv04584

Multicast traffic is being dropped with the resson no-mcast-intrf

CSCvv07864

Multicast EIGRP traffic not seen on internal FTD interface

CSCvv08684

Cluster site-specific MAC addresses not rewritten by flow-offload

CSCvv09396

Stale VPN routes for L2TP, after the session was terminated

CSCvv09944

Lina Traceback during FTD deployment when WCCP config is being pushed

CSCvv12857

ASA gets frozen after crypto engine failure

CSCvv13835

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvv13993

Cisco Firepower 1000 Series Bleichenbacher Attack Vulnerability

CSCvv28997

ASA Traceback and reload on thread name Crypto CA

CSCvv29687

Rate-limit syslogs 780001/780002 by default on ASA

CSCvv31334

Lina traceback and reload seen on trying to switch peer on KP HA with 6.6.1-63

CSCvv32425

ASA traceback when running show asp table classify domain permit

CSCvv33712

Cisco ASA Software Web-Based Management Interface Reflected Cross-Site Scripting Vulnerabi

CSCvv34003

snmpwalk for OID 1.3.6.1.2.1.47.1.1.1.1.5 on ISA 3000 returning value of 0 for .16 and .17

CSCvv34140

ASA IKEv2 VTI - Failed to request SPI from CTM as responder

CSCvv36518

ASA: Extended downtime after reload after CSCuw51499 fix

CSCvv44051

Cluster unit traceback on snp_cluster_forward_and_free_packet due to GRE/IPiniP passenger flows

CSCvv57590

ASA: ACL compilation takes more time on standby

 

 

Revision:  Version 9.12(4)2 – 06/28/2020

Files:  asa9124-2-smp-k8.bin, cisco-asa-fp2k.9.12.4.2.SPA, cisco-asa.9.12.4.2.SPA.csp

Defects resolved since 9.12(4):

 

CSCvb92169

ASA should provide better fragment-related logs and ASP drop reasons

CSCvi42008

Stuck uauth entry rejects AnyConnect user connections

CSCvn64647

ASA traceback and reload due to tcp_retrans_timeout internal thread handling

CSCvn82441

[SXP] Issue with establishing SXP connection between ASA on FPR-2110 and switches

CSCvn95731

ASA traceback and reload on Thread Name SSH

CSCvp77226

ASA traceback and reload on sysopt traffic detailed in multicontext mode

CSCvq87625

ENH: Addition of 'show run all sysopt' to 'show tech' output

CSCvq93836

ENH: Addition of 'show logging setting' to 'show tech' output

CSCvr60195

ASA/FTD may traceback and reload when repeatedly adding/removing multicast commands

CSCvr99642

ASA traceback and reload multiple times with trace "webvpn_periodic_signal"

CSCvs47283

Traffic may match an access-list incorrectly with object-group-search enabled

CSCvs52108

ASA Traceback Due to Umbrella Inspection

CSCvs73754

ASA/FTD: Block 256 size depletion caused by ARP of BVI not assigned to any physical interface

CSCvs82829

Calls fail once anyconnect configuration is added to the site to site VPN tunnel

CSCvt00113

ASA/FTD traceback and reload due to memory leak in SNMP community string

CSCvt36542

Multi-context ASA/LINA on FPR not sending DHCP release message

CSCvt38279

Erase disk0 on ISA3000 causes file system not supported

CSCvt41333

Dynamic RRI route is not destroyed when IKEv2 tunnel goes down

CSCvt43967

Pad packets received from RA tunnel which are less than or equal 46 bytes in length with zeros

CSCvt50946

Stuck uauth entry rejects AnyConnect user connections despite fix of CSCvi42008

CSCvt51349

Fragmented packets forwarded to fragment owner are not visible on data interface captures

CSCvt60190

Cisco ASA and FTD Web Services File Upload Denial of Service Vulnerability

CSCvt63484

ASA High CPU with igb_saleen_io_sfp_mod_poll_thre process

CSCvt64270

ASA is sending failover interface check control packets with a wrong destination mac address

CSCvt68131

FTD traceback and reload on thread "IKEv2 Mgd Timer Thread"

CSCvt80126

ASA traceback and reload for the CLI "show asp table socket 18421590 det"

CSCvt83121

Cisco ASA and FTD Software OSPFv2 Link-Local Signaling Denial of Service Vulnerability

CSCvt90330

ASA traceback and reload with thread name coa_task

CSCvt91521

Crypto accelerator bias setting should be included in show tech

CSCvt92647

Connectivity over the state link configured with IPv6 addresses is lost after upgrading the ASA

CSCvt95517

Certificate mapping for AnyConnect on FTD stops working.

CSCvt98599

IKEv2 Call Admission Statistics "Active SAs" counter out of sync with the real number of sessions

CSCvu00112

tsd0 not reset when ssh  quota limit is hit in ci_cons_shell

CSCvu01039

Traceback: Modifying FTD inline-set tap-mode configuration with active traffic

CSCvu03107

AnyConnect statistics is doubled in both %ASA-4-113019 and RADIUS accounting

CSCvu03562

Device loses ssh connectivity when username and password is entered

CSCvu03675

FPR2100: ASA console may hang & become unresponsive in low memory conditions

CSCvu07602

FPR-41x5: 'clear crypto accelerator load-balance' will cause a traceback and reload

CSCvu07880

ASA on QP platforms display wrong coredump filesystem space (50 GB)

CSCvu08013

DTLS v1.2 and AES-GCM cipher when used drops a particular size packet frequently.

CSCvu12039

Cluster data unit might fail to synchronize SCTP configuration from the control unit after bootup

CSCvu12248

ASA-FPWR 1010 traceback and reload when users connect using AnyConnect VPN

CSCvu12684

HKT - Failover time increases with upgrade to 9.8.4.15

CSCvu15801

Cisco ASA and FTD Software SIP Denial of Service Vulnerability

CSCvu17924

FTD failover units traceback and reload on DATAPATH

CSCvu17965

ASA generated a traceback and reloaded when changing the port value of a manual nat rule

CSCvu20007

Config_XML_Response from LINA is not in the correct format,Lina reporting as No memory available.

CSCvu25030

FTD 6.4.0.8 traceback & reload on thread name : CP processing

CSCvu26296

ASA interface ACL dropping snmp control-plane traffic from ASA

CSCvu26561

WebVPN SSO Gives Unexpected Results when Integrated with Kerberos

CSCvu32698

ASA Crashes in SNMP while joining the cluster when key config-key password-encryption" is present

CSCvu34413

SSH keys lost in ASA after reload

CSCvu38795

FTD firewall unit cannot join the cluster after a traceback due to invalid interface GOID entry

CSCvu40213

ASA traceback in Thread Name kerberos_recv

CSCvu40324

ASA traceback and reload with Flow lookup calling traceback

CSCvu40398

ASAv reload due to FIPS SELF-TEST FAILURE after enabling FIPS

CSCvu42434

ASA: High CPU due to stuck running SSH sessions / Unable to SSH to ASA

CSCvu43924

GIADDR of DHCP Discover packet is changed to the ip address of dhcp-network-scope

CSCvu44910

Cisco ASA Software and FTD Software Web Services Cross-Site Scripting Vulnerability

CSCvu45748

ASA traceback in threadname 'ppp_timer_thread'

CSCvu49625

[PKI] Standard Based IKEv2 Certificate Auth session does second userfromcert lookup unnecessarily

CSCvu53258

FMC pushes certificate map incorrectly to lina

CSCvu55843

ASA traceback after TACACS authorized user made configuration changes

CSCvu65688

IKEv2 CAC "Active SAs" counter out of sync with the real number of sessions despite CSCvt98599

CSCvu72094

ASA traceback and reload on thread name DATAPATH

CSCvu72658

AnyConnect Connected Client IPs Not Advertised into OSPF Intermittently

CSCvu73207

DSCP values not preserved in DTLS packets towards AnyConnect users

CSCvu75581

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvu75594

FTD: Traceback and reload when changing capture buffer options on a already applied capture

CSCvu77095

ASA unable to delete ACEs with remarks and display error "Specified remark does not exist"

CSCvu83178

Dynamic routing protocols summary route not being replicated to standby

CSCvu83309

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvu90727

Native VPN client with EAP-TLS authentication fails to connect to ASA