Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Note: ASA 9.16(3)19 and later requires ASDM 7.18(1)152 or later. The ASA now validates whether the ASDM image is a Cisco digitally signed image. If you try to run an older ASDM image than 7.18(1.152) with an ASA version with this fix, ASDM will be blocked and the message “%ERROR: Signature not valid for file disk0:/<filename>” will be displayed at the ASA CLI. (CSCwb05291, CSCwb05264)

 

Revision:  Version 9.16(3)23 – 09/20/2022

Files:  asa9-16-3-23-smp-k8.bin, cisco-asa-fp1k.9.16.3.23.SPA, cisco-asa-fp2k.9.16.3.23.SPA, cisco-asa.9.16.3.23.SPA.csp

Defects resolved since 9.16(3)19:

 

CSCvz71596

Number of interfaces on Active and Standby are not consistent should trigger warning syslog

CSCvz78816

ASA disconnects the ssh, https session using of Active IP address and Standby MAC address after FO

CSCwa36535

Standby unit failed to join failover due to large config size.

CSCwa47737

ASA/FTD may hit a watchdog traceback related to snmp config writing

CSCwa72929

SNMPv3 polling may fail using privacy algorithms AES192/AES256

CSCwb03704

ASA/FTD datapath threads may run into deadlock and generate traceback

CSCwb31551

When inbound packet contains SGT header, FPR2100 cannot distribute properly per 5 tuple

CSCwb58634

Debug: async_lock_service_one_lock_internal ASA/FTD reload and traceback in thread: DATAPATH

CSCwb89963

ASA Traceback & reload in thread name : Datapath

CSCwc07262

Standby ASA goes to booting loop during configuration replication after upgrade to 9.16(3).

CSCwc11511

FTD: SNMP failures after upgrade to 7.0.2

CSCwc28806

ASA Traceback and Reload on process name Lina

CSCwc36905

ASA  traceback and reload due to "Heap memory corrupted at slib_malloc.c

CSCwc38567

ASA/FTD may traceback and reload while executing SCH code

CSCwc40381

ASA : HTTPS traffic authentication issue with Cut-through Proxy enabled

CSCwc44289

FTD - Traceback and reload when performing IPv4 <> IPv6 NAT translations

CSCwc45108

ASA/FTD: GTP inspection causing 9344 sized blocks leak

CSCwc45397

ASA HA - Restore in primary not remove new interface configuration done after backup

CSCwc48375

Inbound IPSEC SA stuck inactive - many inbound SPIs for one outbound SPI in "show crypto ipsec sa"

CSCwc50887

FTD - Traceback and reload on NAT IPv4<>IPv6 for UDP flow redirected over CCL link

CSCwc50891

MPLS tagging removed by FTD

CSCwc52351

ASA/FTD Cluster Split Brain due to NAT with "any" and Global IP/range matching broadcast IP

CSCwc53280

ASA parser accepts incomplete network statement under OSPF process and is present in show run

CSCwc54984

IKEv2 rekey - Responding Invalid SPI for the new SPI received right after Create_Child_SA response

CSCwc60037

ASA fails to rekey with IPSEC ERROR: Failed to allocate an outbound hardware context

CSCwc61912

ASA/FTD  OSPFv3 does not generate messages Type 8 LSA for IPv6

CSCwc79366

During the deployment time, device got stuck processing the config request.

 

 

Revision:  Version 9.16(3)19 – 08/10/2022

Files:  asa9-16-3-19-smp-k8.bin, cisco-asa-fp1k.9.16.3.19.SPA, cisco-asa-fp2k.9.16.3.19.SPA, cisco-asa.9.16.3.19.SPA.csp

Defects resolved since 9.16(3)15:

 

CSCvy50598

BGP table not removing connected route when interface goes down

CSCvz36903

ASA traceback and reload while allocating a new block for cluster keepalive packet

CSCwa59907

LINA observed traceback on thread name "snmp_client_callback_thread"

CSCwa97917

ISA3000 in boot loop after power cycle

CSCwb05291

Cisco ASDM and ASA Software Client-side Arbitrary Code Execution Vulnerability

CSCwb17963

Unable to identify dynamic rate liming mechanism & not following msg limit per/sec at syslog server.

CSCwb52401

Cisco Firepower Threat Defense Software Privilege Escalation Vulnerability

CSCwb94190

ASA graceful shut down when applying ACL's with forward reference feature and FIPS enabled.

CSCwc02488

ASA/FTD may traceback and reload in Thread Name 'None'

CSCwc03069

Interface internal data0/0 is up/up from cli but up/down from SNMP polling

CSCwc09414

ASA/FTD may traceback and reload in Thread Name 'ci/console'

CSCwc10483

ASA/FTD - Traceback in Thread Name: appAgent_subscribe_nd_thread

CSCwc10792

ASA/FTD IPSEC debugs missing reason for change of peer address and timer delete

CSCwc11597

ASA tracebacks after SFR was upgraded to 6.7.0.3

CSCwc11663

ASA traceback and reload when modifying DNS inspection policy via CSM or CLI

CSCwc13017

FTD/ASA traceback and reload at at ../inspect/proxy.h:439

CSCwc13994

ASA - Restore not remove the new configuration for an  interface setup after backup

CSCwc18312

show nat pool cluster commands run within EEM scripts lead to traceback and reload

CSCwc23695

ASA/FTD cannot parse UPN from SAN field of user's certificate

CSCwc24906

ASA/FTD traceback and reload on Thread id: 1637

CSCwc27797

ASA mgmt ip cannot be released

CSCwc28532

9344 Block leak due to fragmented GRE traffic over inline-set interface inner-flow processing

CSCwc28854

Incorrect IF-MIB response when failover is configured on multiple contexts

CSCwc32246

NAT64 translates all IPv6 Address to 0.0.0.0/0 when object subnet 0.0.0.0 0.0.0.0 is used

 

 

Revision:  Version 9.16(3)15 – 06/28/2022

Files:  asa9-16-3-15-smp-k8.bin, cisco-asa-fp1k.9.16.3.15.SPA, cisco-asa-fp2k.9.16.3.15.SPA, cisco-asa.9.16.3.15.SPA.csp

Defects resolved since 9.16(3)14:

 

CSCvw82067

ASA/FTD 9344 blocks depleted due to high volume of fragmented traffic

CSCvz69729

Unstable client processes may cause LINA zmqio traceback on FTD

CSCwa41936

Cisco FTD Bleichenbacher Attack Vulnerability

CSCwb05148

Cisco ASA Software and FTD Software SNMP Denial of Service Vulnerability

CSCwb07908

Standby FTD/ASA sends DNS queries with source IP of 0.0.0.0

CSCwb08644

ASA/FTD traceback and reload at IKEv2 from Scaled S2S+AC-DTLS+SNMP long duration test

CSCwb19648

SNMP queries for crasLocalAddress are not returning the assigned IPs for SSL/DTLS tunnels.

CSCwb53172

FTD: IKEv2 tunnels flaps every 24 hours and crypto archives are generated

CSCwb53328

ASA/FTD Traceback and reload caused by Smart Call Home process sch_dispatch_to_url

CSCwb54791

ASA DHCP server fails to bind reserved address to Linux devices

CSCwb66761

Cisco Firepower Threat Defense Software Generic Routing Encapsulation DoS Vulnerability

CSCwb67040

FP4112|4115 Traceback & reload on Thread Name: netfs_thread_init

CSCwb68642

ASA traceback in Thread Name: SXP CORE

CSCwb71460

ASA traceback in Thread Name: fover_parse and triggered by snmp related functions

CSCwb73248

FW traceback in timer infra / netflow timer

CSCwb74571

PBR not working on ASA routed mode with zone-members

CSCwb79812

RIP is advertising all connected Anyconnect users and not matching route-map for redistribution

CSCwb80559

FTD offloads SGT tagged packets although it should not

CSCwb80862

ASA/FTD proxy arps any traffic when using the built-in 'any' object in translated destination

CSCwb83388

ASA HA Active/standby tracebacks seen approximately every two months.

CSCwb83691

ASA/FTD traceback and reload due to the initiated capture from FMC

CSCwb85633

Snmpwalk output of memory does not match show memory/show memory detail

CSCwb87498

Lina traceback and reload during EIGRP route update processing.

CSCwb87950

Cisco ASA Software and FTD Software Web Services Interface Denial of Service Vulnerability

CSCwb90074

ASA: Multiple Context Mixed Mode SFR Redirection Validation

CSCwb90532

ASA/FTD traceback and reload on NAT related function nat_policy_find_location

CSCwb92709

We can t monitor the interface via "snmpwalk" once interface is removed from context.

CSCwb93932

ASA/FTD traceback and reload with timer services assertion

CSCwb94312

Unable to apply SSH settings to ASA version 9.16

CSCwb97251

ASA/FTD may traceback and reload in Thread Name 'ssh'

CSCwb63827 

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DoS

 

 

Revision:  Version 9.16(3)14 – 05/19/2022

Files:  asa9-16-3-14-smp-k8.bin, cisco-asa-fp1k.9.16.3.14.SPA, cisco-asa-fp2k.9.16.3.14.SPA, cisco-asa.9.16.3.14.SPA.csp

Defects resolved since 9.16(3)3:

 

CSCvw56551

ASA displays cosmetic NAT warning message when making the interface config changes

CSCvy67765

FTD VTI reports TUNNEL_SRC_IS_UP false despite source interface is up/up and working

CSCvy73130

FP4100 platform: Active-Standby changed to dual Active after running "show conn command

CSCvy75724

ZMQ OOM due to less Msglyr pool memory in low end platforms

CSCvz09106

Cisco ASA and FTD Software SSL VPN Denial of Service Vulnerability

CSCvz60142

ASA/FTD stops serving SSL connections

CSCvz68713

PLR license reservation for ASAv5 is requesting ASAv10

CSCvz70539

Loggerd process is getting killed due to OOM under high logging rate

CSCvz70958

High Control Plane CPU on StandBy due to dhcpp_add_ipl_stby

CSCvz94573

MIO heartbeat failure caused by heartbeat dropped by delay

CSCwa35200

Some syslogs for AnyConnect SSL are generated in admin context instead of user context

CSCwa43311

Snort blocking and dropping packet, with bigger size(1G) file download

CSCwa56449

ASA traceback in HTTP cli EXEC  code

CSCwa61361

ASAv traceback when SD_WAN ACL enabled, then disabled (or vice-versa) in PBR

CSCwa62025

IPv6: Some of egress interfaces of global and user vrf routes are missing in asp table

CSCwa68552

All type-8 passwords are lost upon upgrade from ASA 9.12-9.15 to 9.16, failover gets disabled

CSCwa68660

FTP inspection stops working properly after upgrading the ASA to 9.12.4.x

CSCwa72530

FTD: Time gap/mismatch seen when new node joins a Cluster Control node under history

CSCwa73172

ASA reload and traceback in Thread Name: PIX Garbage Collector

CSCwa79494

Traffic keep failing on Hub when IPSec tunnel from Spoke flaps

CSCwa85043

Traceback: ASA/FTD may traceback and reload in Thread Name 'Logger'

CSCwa89243

SNMP no longer responds to polls after upgrade to 9.15.1.17

CSCwa91090

SSL handshake logging showing unknown session during AnyConnect TLSv1.2 Session establishment

CSCwa94894

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-4-9608'

CSCwa95079

ASA/FTD Traceback and reload due to NAT configuration

CSCwa96327

Incorrect ifHighSpeed value for a interfaces that are port channel members

CSCwa96759

Lina may traceback and reload on tcpmod_proxy_handle_mixed_mode

CSCwa98684

Console has an excessive rate of warnings during policy deployment

CSCwa99931

update_mem_reference process taking high CPU in HA pair

CSCwb00595

Mempool_DMA allocation issue / memory leakage

CSCwb01700

ASA: SSH and ASDM sessions stuck in CLOSE_WAIT causing lack of MGMT for the ASA

CSCwb02060

snmp-group host with Invalid host range and subnet causing traceback and reload

CSCwb06847

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-9-11543'

CSCwb07981

Traceback: Standby FTD reboots and generates crashinfo and lina core on thread name cli_xml_server

CSCwb09219

ASA/FTD: OCSP may fail to work after upgrade due to "signer certificate not found"

CSCwb16920

CPU profile cannot be reactivated even if previously active memory tracking is disabled

CSCwb17187

SNMP cores are generated every minute while running snmpwalk on QP-HA

CSCwb18252

FTD/ASA: Traceback on BFD function causing unexpected reboot

CSCwb24039

ASA traceback and reload on routing

CSCwb25809

Single Pass - Traceback due to stale ifc

CSCwb31699

Primary takes active role after reload

CSCwb32841

NAT (any,any) statements in-states the failover interface and resulting on Split Brain events

CSCwb34035

ASA CLI gets hung randomly while configuring SNMP

CSCwb40001

Long delays when executing SNMP commands

CSCwb43018

Implement SNP API to check ifc and ip belongs to HA LU or CMD interface

CSCwb50405

ASA/FTD Traceback in crypto hash function

CSCwb51707

ASA Traceback and reload in process name: lina

CSCwb53191

Certificate validation fails post upgrade to 9.17.1

CSCwb59465

ASA/FTD may traceback (watchdog) and reload when generating a syslog from the VPN Failover subsystem

CSCwb59488

ASA/FTD Traceback in memory allocation failed

 

 

Revision:  Version 9.16(3)3 – 04/20/2022

Files:  asa9-16-3-3-smp-k8.bin, cisco-asa-fp1k.9.16.3.3.SPA, cisco-asa-fp2k.9.16.3.3.SPA, cisco-asa.9.16.3.3.SPA.csp

Defects resolved since 9.16(3):

 

CSCvz09106

Cisco ASA and FTD Software SSL VPN Denial of Service Vulnerability