Cisco ASA Interim Release Notes

The software images listed below are Interim releases. They contain bug fixes which address specific issues found since the last Feature or Maintenance release. The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available.

Version 9.18.4.66 – August 13, 2025

Defects resolved in this release:

CSCwb07908Standby FTD/ASA sends DNS queries with source IP of 0.0.0.0
CSCwh11677saml idp names longer than 128 characters cannot be used
CSCwh13312Disable Notification Daemon heartbeat action
CSCwi15787Management access over VPN not working when NAT exempt is configured with any->any
CSCwi57476interface idb logging log rotation to FXOS logrotate utility
CSCwj29599FDM bootstrap might be interrupted by extra reboot due to firmware upgrade
CSCwj32736SNMP walk does not work if IP is configured after SNMP is configured on ngfw management interface.
CSCwk88225Critical fault : [FSM:FAILED]: user configuration(FSM:sam:dme:AaaUserEpUpdateUserEp)
CSCwm05960Generated Crypto checksum changes without configuration change
CSCwm07419ldap.conf does not get generated using hostname impacting external radius authentication
CSCwm86414ASA - Failover config resync failed and unexpected reboot occurred
CSCwm92310FQDNs are unresolved via DNS on data interface after reboot or traceback
CSCwn06520ASA/FTD may traceback and reload in Thread Name 'DATAPATH-2-2854'
CSCwn27872Big chunk of Memory of around 25KB is being allocated on Stack in "eigrp_interface_ioctl" API
CSCwn32978Traceback and reload in Thread Name Datapath
CSCwn36712NAT divert for 8305 on standby not updating post failover causing the Primary, standby FTD to show offline on FMC
CSCwn38761DNS FQDN obj doesn't go unresolved upon FQDN obj deleted on server/intf to reach sever is down in 7.7
CSCwn39081SNMP walk results in ASCII value for IPSEC Peer instead of an IP address.
CSCwn59032FCM GUI became inaccessible after upgrading to ASA 9.18.4.22 | FPR 2130 Platform Mode
CSCwn60726Traceback and reload with Thread Name: vtemplate process
CSCwn80419Need the SVC Rx/Tx queue as a configurable option
CSCwn81118RTSP packets getting stuck in transmit queue leading to 9k blocks exhaustion.
CSCwn81995Traceback and Reload caused by Memory corruption with SNMP inspection enabled
CSCwn96929ASA: Traceback and Reload Under Thread Name SSH
CSCwn97630FTD data unit in cluster experienced traceback and rebooted
CSCwn98402Debuggability: FP2100 port-channel interfaces flap after upgrade
CSCwo00102Snort3 trimming packets with invalid sequence number due to bad window size information received
CSCwo00332Firepower wiping SSL trustpoint config after reloading.
CSCwo00702Community lists should not throw an error until the last item in the list is being deleted
CSCwo08306Command authorization fallback to Local only works for users with privilege 15.
CSCwo08724Active HA unit goes into failed state before peer unit gets into a ready state during snort failure
CSCwo09195Traceback and reload during the deployment after disabling FQDNs.
CSCwo18838ASA/FTD may traceback and reload in Thread Name 'lina_exec_startup_thread'
CSCwo19762Unable to rejoin data node in cluster after re-enabling mac-address auto in multi-context mode
CSCwo24856FPR 2140 HA 7.4.2.1 (Snort 2) - 9K block depletion causing slowdown of all traffic through firewall
CSCwo31094Virtual ASA Traceback and Reload Caused by Disk Access Issues with NFS Enabled
CSCwo35783Enhance Debugging for add/update/withdraw of routes with neighbors
CSCwo35788Serviceability Enhancement - New 'show bgp internal' command for advanced debugging
CSCwo35810show bgp update-group a.b.c.d displays "no such neighbor" when there is a valid neighbor
CSCwo35938IPv6 Management communication is lost due to a missing management-only multicast route.
CSCwo44732ARP is silently dropping packet for an unreachable next hop
CSCwo49425Logging recipient-address not overriding the logging mail message severity levels
CSCwo54996Traffic failure due to 9344 blocks leak
CSCwo58191FTD: Large Delay in packets being inspected by snort
CSCwo58260Add "built" and "teardown" messages for the GRE | IPinIP connections to the Lina syslog
CSCwo60609DNS doctoring not working correctly if the doctoring rule is of type dynamic and has any interface
CSCwo61241Logical App Stuck in 'Start Failed' Due to checkSystemCPUs Failure
CSCwo65060FTD HA | Same MAC for port-channels causing network outage.
CSCwo66872snmp_logging_thread is utilizing high CPU in control plane
CSCwo71052FPR1010 Ethernet1/1 trunk port is not passing Vlan traffic after a reload
CSCwo75810SNMP configuration is not applied consistently across same FTDs type and version
CSCwo78969Traceback in thread name DATAPATH when a unit is re-joining the cluster
CSCwo79028Post-Failover FQDN Resolution Deferred Until Next DNS Poll Interval
CSCwo79080ENH: UDP traffic flow requires Initiator and Responder fields in the "show conn detail" output.
CSCwo79798Cryptochecksum changed after reloading.
CSCwo80223BFD packets are not dropped for single-hop BFD sessions received via alternate path
CSCwo82639Local user details not replicated to data nodes in a cluster setup.
CSCwo82658ASDM: Displays Error of Keypair already exists when adding an identity certificate.
CSCwo87763ASA/FTD: Primary standby unit becomes Active after reload in HA set up
CSCwo88204ASA/FTD traceback and reload triggered by the Smart Call Home process in sch_dispatch_to_url.
CSCwo91436FPR 4125 Multi instance: High Snort and System Core CPU Usage (100%) Triggering FMC Critical Alerts
CSCwo91965ASAv restarts unexpectedly
CSCwo94483LINA stays inactive without reloading after traceback on non-CP thread
CSCwo97439ACL: ASA may show false "OOB Access-list config change detected" warning after AAA authorization command is applied
CSCwo98752Traceback in threadname DATAPATH while trying to re-join cluster.
CSCwp04235ASA traceback and reload
CSCwp06882high CPU usage after ASA upgrade from 9.20.3.9 to 9.20.3.16 running on Hyper-V
CSCwp11382ASA/FTD: the ssl trust-point command deleted after a reload
CSCwp13540Wrong URL incorrectly displayed for file upload with Japanese text in file path for client-less VPN
CSCwp16529Negative value displayed for buffer drops when using " show cluster info load-monitor details"
CSCwp17700Syslog format is not properly printed when EMBLEM format is enabled at least in one syslog host
CSCwp22214Multiple mail drops and enq failures are seen while traffic is going through the box.
CSCwp33410dmesg and kern.log file flooded with Tx Queue=0 logs
CSCwp34610IKEv2-EAP Authentication Fails with Windows and MacOS Native VPN Clients
CSCwp37284"CSRF Token Mismatch" error seen when users click logout from Clientless VPN page
CSCwp39319ASA Memory leak while processing large CRLs.
CSCwp89969Prolonged delays in firewall restart/reboot completion
CSCwp97862If failover IPSEC PSK is 78 characters or greater HA breaks with "Could not set failover ipsec pre-shared-key"
CSCwq35960OSPF: Lina Traceback and Reload on Both Units in High Availability Setup.


Version 9.18.4.57 – April 10, 2025

Defects resolved in this release:

CSCwk46737ASA on HA: alloc_ch() alloc from chunk mem Failed message on one context in Standby device
CSCwn90900High ASA/FTD memory usage due to polling of RA VPN related SNMP OIDs
CSCwn90958Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerability
CSCwo00141Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability
CSCwo00880Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability
CSCwo08042ASAv reloaded unexpectedly with traceback on Unicorn Proxy Thread
CSCwo09060SSL trustpoint with 4096 bit RSA keys not allowed by ASA if renewed via CLI
CSCwo15022Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability
CSCwo15023Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability
CSCwo15027Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
CSCwo41250Traceback & Reload in thread named: DATAPATH-1-23988 during low memory condition


Version 9.18.4.53 – March 5, 2025

Defects resolved in this release:

CSCwe88492Banner login does not display when configured
CSCwe92324FPR31xx - SNMP poll reports incorrect FanTray Status at Down while actually operational
CSCwf04460The fxos directory disappears after cancelling show tech fprm detail command with Ctr+c is executed.
CSCwf25454Stale anyconnect entries causing issues with routing
CSCwh17965[Display]FXOS: PC member interface is shown as down & unassociated/unassigned after reload
CSCwj57435Cleanup stale logrotate files
CSCwj61086High CPU usage in svc_sam_dme process during deployment post breaking cluster or deleting inline-set
CSCwk28058FTD memory depletion resulting in traceback and reload
CSCwk48628FTD/FxOS - Upgrade/erase configuration result in App-instance 'Operational State: Starting'
CSCwm36631FTD Secondary Unit got stuck in Bulk sync state.
CSCwm74289NAT traps have to be rate-limited
CSCwm98278TCP Conn not being flagged as Half-Closed after receiving the ACK for the FIN.
CSCwn00475Memory Blocks 80 and 9344 leak due to priority-queue
CSCwn14130FTD cluster to traceback and reload after extended PAT is enabled
CSCwn19706Admin users are prompted to change local password when authenticating to external server
CSCwn22565Frequent route updates causes routes to get removed causing outages
CSCwn39826HA should prevent honouring failover requests while copy/config-sync/rollback is in progress
CSCwn40572MI: Vlan info is not applied at FXOS level when Virtual MAC is configured
CSCwn44335FXOS - Download command generates an extra "/" over HTTP and HTTPS GET requests
CSCwn45510S2S VPN tunnel Child SA unsuccessful renegotiation
CSCwn46855LINA may observe random traceback with Netflow configured
CSCwn47308Critical health alerts 'user configuration(FSM.sam.dme.AaaUserEpUpdateUserEp)' on FPR 1100/2100/3100
CSCwn63839Traceback in thread name Lina on configuring arp permit-nonconnected with BVI
CSCwn65415ASA: floating-conn not closing UDP conns if conn was created without ARP entry for next hop
CSCwn73351Asia/Bangkok timezone option not listed in ASA running on firepower1k
CSCwn73399Cisco Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability
CSCwn75667Banner motd does not display when configured
CSCwn76079SSH works in admin context but doesn't work in any user context after changing ssh key-exchange
CSCwn79553Unreachable LDAP/AD referrals may cause delays or timeouts in external authentication on FTD
CSCwn80400Slow download speeds with AnyConnect over TLS on networks with high latency
CSCwn80765ISA3000 with ASA Refuses SSH Access If CiscoSSH is Enabled
CSCwn84557Lina traceback and reload due to "spin_lock_fair_mode_enqueue"
CSCwn86002core corruption still seen with switching to quick core feature
CSCwn91612Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerability
CSCwn92894Occasionally, 'show chunkstat top-usage' output does not show all entries
CSCwn93319ASA/FTD may traceback and reload in Thread Name "DATAPATH"
CSCwo01557ASA traceback and reload on DATAPATH thread due to memory corruption
CSCwo09618Enabling debugs with EEM fails


Version 9.18.4.52 – January 28, 2025

Defects resolved in this release:

CSCwf42097PSEQ (Power-Sequencer) firmware may not be upgraded with bundled FXOS upgrade
CSCwi57783Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Access Control Rules Bypass Vulnerability
CSCwi65260Modification of destination entries failed, when Source Object Group and Destination Object Group contain same inner object-group
CSCwi94356Lina traceback and reload in Thread Name: cli_xml_request_process
CSCwk21540ASA/FTD - Unable to establish RAVPN sessions
CSCwk63586App instance stuck in STOP_FAILED with error message
CSCwm28007Browser redirects to blank page when the user clicks the WebVPN bookmark
CSCwm35730LINA may traceback in Thread Name: Datapath with NAT config
CSCwm37455ASA/FTD will allow local IP pool with invalid netmask
CSCwm44412FTD inline-set ignore reverse flag for inject/rewrite
CSCwm51874FXOS: messages rotates every 40 minutes due to Notification Daemon messages' being spammed
CSCwm63868FTD - Missing routes on BGP advertised-routes after FTD HA failover event
CSCwm68211ASA traceback and reload on thread snmp_inspect
CSCwm70835ASA traceback and reload due to stack overflow while using APCF file
CSCwm71265ASA traceback and reload on thread DATAPATH when processing gtpv1 end marker msg for PDP
CSCwm96280FTD device stuck in rommon mode after pressing reset button
CSCwm96652Cluster assigning wrong nat for unit, traffic not being forwarded properly back to unit
CSCwm97054ASA/FTD traceback and reload with high rate of SIP connections
CSCwn01281GTP inspection not allowing GTP data packets if session create response has cause type 18
CSCwn03446When capture enabled on cluster interface, it always includes CCL IP along with the configured rule
CSCwn03835ASA/FTD may traceback and reload in Thread Name 'SSH Ctxt Thread'
CSCwn13187ASA upgrade failing from 9.20.2.21 to the target version 9.20.3.4
CSCwn14447ASA/FTD may traceback and reload in Thread Name 'ldap_client_thread'
CSCwn15104FTD reload with traceback on swapcontext function
CSCwn15589Need unified package/fix for pseq and associated rommon fix for pseq upgrade failure
CSCwn17121ASA/FTD may traceback and reload in Thread Name 'cli_xml_request_process'.
CSCwn19739HA would bring data interfaces up while moving from cold standby to failed state
CSCwn20024ASA may traceback and reload in Thread Name 'ssh'
CSCwn21584Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Web Services Denial of Service Vulnerability
CSCwn22036FTD: Management0/0 status went down, line protocol is up after upgrade
CSCwn22456GTPv2 IE-type 157 (Signaling Priority Indication) is dropped with reason as unknown IE type
CSCwn24577ASA booting process may freeze when including 'no pim' or 'no igmp' config
CSCwn24596FTD may traceback and reload while executing "network-service reload" command and if it gets stuck
CSCwn26165FTD/ASA May Traceback and Reload - During Deployment / Radius changes - Due to Radius Packets
CSCwn27819Jumbo frame packets are being fragmented
CSCwn31653FTD may traceback and reload in Thread Name "FPRLI_FPR4K-SM-32"
CSCwn34259Monitored interfaces may go in waiting state after upgrade to 9.20.3.7
CSCwn34659Firewall not initiating TCP request even after receiving the TC bit set in DNS response
CSCwn34707Multiple Unicorn Admin Handler processes consume all the control plane CPU.
CSCwn35470Serviceability : FQDN Packet based debug and capture trace support
CSCwn39780FTD Deployment Resilience: Skip non-critical / non-existing commands to avoid deployment failures.
CSCwn42949Implementing forwarder flow on non-owner units handling distributed secondary flow connections


Version 9.18.4.50 – November 14, 2024

Defects resolved in this release:

CSCwb77894Firepower 1000/2100 may boot to ROMMON mode
CSCwc57500Remove bootlogd package from FXOS to avoid ASA boot log problems
CSCwf049833100 unit failed to join the cluster with error "configured object (sys/switch-A/slot-2) not found"
CSCwh23124Secondary/Standby node shows flapping between Ready & Failed when mgmt interface is shutdown
CSCwi05709FTD reboot due to filesytem event
CSCwj72013PAT communication via using PAT pool fails for about 40 seconds when a device joins a cluster
CSCwj98872eth0 may not be properly initialized after reboot
CSCwk11989Accepting duplicate object/group-object into object-group from multiple ssh sessions
CSCwk30049ASA/FTD May traceback & reload citing Thread Name 'lina' as the faulting thread.
CSCwk42676Virtual ASA/FTD may traceback and reload in thread PTHREAD
CSCwk67859FTD and FXOS: RADIUS Protocol Spoofing Vulnerability (Blast-RADIUS): July 2024
CSCwk71227FTD running on FPR 2k with LDAP skips backslash when updating ldap.conf
CSCwm06393Changes in port-channel membership or member status may cause periodic OSPF/EIGRP adjacency flaps
CSCwm08231Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Network Address Translation DNS Inspection Denial of Service Vulnerability
CSCwm30731The ASA's OSPF routing table is not properly synchronized with the neighbors
CSCwm33529FXOS MTU Handling for Front Panel and Uplink Ports on Firepower devices require improvement
CSCwm33613Default Group Policy is applied when receiving multiple Group Policies in SAML assertion attributes
CSCwm35751FPR3100: Interface may go to half duplex speed is hardcoded to 100mbps
CSCwm41847Serviceability to capture PDTS writing/reading block to help root cause CSCwm36314
CSCwm42000FTD/ASA may traceback and reload in DATAPATH thread
CSCwm49154FXOS fault F1738 seen in deploymet with Error: CSP_OP_ERROR. CSP signature verification error
CSCwm49410Misconfigured Cross-Origin-Opener-Policy
CSCwm49721ASA Traceback and Reload due to MEMORY CORRUPTION WAS DETECTED
CSCwm49782enhance sma 2nd cruz heartbeat logging
CSCwm50591ASA/FTD: Inbound IPsec packets are dropped when IPsec offload is enabled with VTI and sub-interface
CSCwm52264Not able to remove or clear Fault "The password encryption key has not been set."
CSCwm52931ASA/FTD may traceback and reload in Thread Name "fover_parse"
CSCwm56864show run access-list command returns warning
CSCwm60536SQLNet traffic getting dropped intermittently in Clustering data unit.
CSCwm61282ASA/FTD: RA VPN tunnel causing memory leak leading to traceback & Reload
CSCwm78351Potential High CPU usage in Multi-Context Cluster setup with unconditional execution of capture code
CSCwm85228ASA/FTD may traceback and reload in Thread Name "IKEv2 Daemon" while joining failover
CSCwm89523'no capture /all' failed to disable capture completely in the backend, causing high datapath CPU
CSCwm90905GTP inspection drops packet with error ERROR-DROP:MsgType:32
CSCwm92397LINA core observed pointing to "IP RIB Update" thread
CSCwm95070Cisco Secure Firewall ASA and Secure FTD Software for FP 2100 Series IPv6 over IPsec DoS Vulnerability


Version 9.18.4.47 – October 9, 2024

Defects resolved in this release:

CSCwi57670RAVPN SAML: External browser gives misleading message when FTD/ASA fails to parse assertion
CSCwi98274unzip 5.52 is from 2005 is contains multiple vulnerabilities
CSCwj15125ASA/FTD may traceback and reload in Thread Name 'lina' related to Netflow timer infra
CSCwk08241FTD is not resolving FQDN for ACLs intermittently
CSCwk31371NAT_HARDEN: CGNAT breaks when mapped ifc is configured as any
CSCwk40335Trigger Alert/Warning when the associated FQDN IDs of an IP address surpasses the set limit of 8
CSCwk42676Virtual ASA/FTD may traceback and reload in thread PTHREAD
CSCwk61157FTD LINA Traceback and Reload dhcp_daemon Thread
CSCwk63733HA-monitored interfaces are going into "waiting" state and subsequently to "Failed"
CSCwk67859FTD and FXOS: RADIUS Protocol Spoofing Vulnerability (Blast-RADIUS): July 2024
CSCwk71866ASA: Site-to-Site VPN between contexts on the same device drops traffic due to 'ipsec-tun-down'
CSCwk71992BlastRADIUS vulnerability phase-1 fix for pix-asa - Message Authenticator
CSCwk75956ASA/FTD may traceback and reload in Thread Name SSH
CSCwk87457ASA/FTD may traceback and reload in Process Name "lina" after device was reloaded
CSCwk88182FTDv50 traceback during normal operation at PTHREAD-8141 spin_lock_fair_mode_enqueue
CSCwk89836ASA/FTD may traceback and reload in Thread Name 'strlen'
CSCwk94382FTD: Lina might fail to respond to CONFIG_XML_REQUEST leading to stuck deployments
CSCwm01544Lina traceback and reload in data-path thread
CSCwm02801Unstable HA causing depolyment failure
CSCwm04650Increase memory usage leading to tracebacks in Lina.
CSCwm05520Disable cluster syn cookie decoding when FTD cluster is deployed with inline-set
CSCwm07389CGroups errors in ASA Syslog during every reboot
CSCwm08232Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Network Address Translation DNS Inspection Denial of Service Vulnerability
CSCwm13141FTD CLISH/CLI gets locked up when trying to run any show command
CSCwm13199SIP traffic is affected due to unexpected behavior with NAT untranslations.
CSCwm14509Wrong drops seen with Invalid length for 23, 24 and 25 IE-Types during GTP inspection
CSCwm14561ASA/FTD may traceback and reload in Thread Name 'fover_parse'
CSCwm14729CSF 3100 series not rebooting after power outage, requiring manual power cycle
CSCwm42745Dynamic Site-to-Site tunnels stuck in IN-NEG state When IKE_AUTH Is Missed
CSCwm49153Cisco Adaptive Security Appliance Software SSH Server Resource DoS Vulnerability


Version 9.18.4.40 – August 29, 2024

Defects resolved in this release:

CSCwa82791ENH: Support for snapshots of RX queues on InternalData interfaces when "Blocks free curr" goes low
CSCwf34069Cisco ASA and FTD Remote Access SSL VPN Authentication Targeted Denial of Service Vulnerability
CSCwh51872Message asa_log_client exited 1 time(s) seen multiple times
CSCwh83517VTI tunnel goes down due to route change detected in VRF scenario
CSCwi44912ISA3000 Traceback and reload boot loop
CSCwi90751FTD/ASA - SNMP queries using snmpwalk are not displaying all "nameif" interfaces
CSCwj08696FTD lina traceback Thread Name: Non-Lina Process data Init Thread
CSCwj31918Segmentation fault with "logger_msg_dispatch" while HA sync
CSCwj35701Dns-guard prematurely closing conn due to timing condition
CSCwj53725Traceback observed while applying 'no failover' and 'failover' in the ASA standby
CSCwj83185FTD/ASA : Standby FTD traceback and reload after enabling memory tracking
CSCwj83634Seeing message "reg_fover_nlp_sessions: failover ioctl C_FOREG failed"
CSCwj87501ASA/FTD may traceback and reload in Thread Name 'fover_FSM_thread'
CSCwk00604ASA Fails to initiate AAA Authentication with IKEv2-EAP and Windows Native VPN Client
CSCwk05800ASA/FTD SNMP polling fails due to overlapping networks in snmp-server host-group
CSCwk06573Serviceablity : Improve routing infra debugs and add new for error conditions
CSCwk08476FTD/ASA traceback and reload due to 'show bgp summary' memory leak
CSCwk10884Connectivity failure due to mismatch between l2_table and subinterface mac address
CSCwk11983High LINA CPU observed due to NetFlow due to 'flow-export delay flow-create' configuration
CSCwk13132FTD/ASA 1550 blocks may get exhausted while sending logs to TCP syslog server
CSCwk22574Remove SGT frames/packets to allow VTI decryption
CSCwk24176FTD/ASA - VPN traffic flowing through the device may trigger tracebacks and reloads.
CSCwk26968Backup feature does not save/restore DAP configuration in multiple context mode.
CSCwk27175ASA/FTD: Substantial increase in the time taken to load configuration
CSCwk35710FTD/LINA may traceback and reload when "show capture" command is executed in EEM script
CSCwk45975TLS1.3 Decryption configuration on SSL policy is affecting DND traffic.
CSCwk48975Packet-tracer output incorrectly appends 'control-plane' to drops for data-plane access-group
CSCwk53369Cisco ASA and FTD Software Remote Access VPN Denial of Service Vulnerability
CSCwk62381ASA might traceback and reload due to ssh/client hitting a null pointer while using SCP.
CSCwk68759Split brain issue in HA failover due to which outage happened on customer network
CSCwk69742FTD: Policy deployment failed due to mismatch of checksum.


Version 9.18.4.34 – July 18, 2024

Defects resolved in this release:

CSCwh09968ASA/FTD: Traceback and reload due to NAT change
CSCwh10931ASA/FTD traceback and reload when invoking "show webvpn saml idp" CLI command
CSCwh63211Lina core at snp_nat_xlate_verify_magic.part and soft traces
CSCwh70874FTD: Policy Deployment failure due to abort as no progress
CSCwh78118ASA/FTD traceback and reload on process fsm_send_config_info_initiator
CSCwi05240ASA - Traceback the standby device while HA sync ACL-DAP
CSCwj17447ASA/FTD may traceback and reload in Thread Name 'DATAPATH-6-26174'
CSCwj19125Cisco ASA and FTD NSG Access Control List Bypass Vulnerability
CSCwj20804Cisco ASA and FTD Software VPN Web Server Limited Information Disclosure Vulnerability
CSCwj24828Issue when two FQDN objects with same IP are added in source or destination (FTD/ASA)
CSCwj43345SNMP poll for some OIDs may cause CPU hogs and high latency can be observed for ICMP packets
CSCwj49745Cisco ASA and FTD VPN Web Client Services Cross-Site Scripting Vulnerabilities
CSCwj73061SNMP OID for CPUTotal1min omits snort cpu cores entries when polled
CSCwj74323ASAv Memory leak involving PKI/Crypto for VPN
CSCwj81743FTD - Trace back and reload due to NAT involving fqdn objects
CSCwj82247Cisco ASA and FTD SSL VPN Memory Management Denial of Service Vulnerability
CSCwj82736TLS Handshake Fails if Segmented or Fragmented Client Hello Packet is Received Out of Order
CSCwj86116High LINA CPU observed due to NetFlow configuration
CSCwj86320Standby Unit Interfaces enter "Waiting" Status Post-FTD Upgrade Due to Incorrect "Hello" Message MAC
CSCwj88400FTD may traceback and reload in process name lina while processing appAgent msg reply
CSCwj89264FTD HA: Traceback and reload in netsnmp_oid_compare_ll
CSCwj99043Cisco ASA & FTD Software IKEv2 Denial of Service Vulnerability
CSCwj99068Cisco ASA and FTD Software IKEv2 VPN Denial of Service Vulnerability
CSCwk02804WebVPN connections stuck in CLOSEWAIT state
CSCwk02928ASA/FTD may traceback and reload in Thread Name PTHREAD
CSCwk04290FPR 21xx - Traceback in Process Name: lina-mps during normal operations
CSCwk04492ASA CLI hangs with 'show run' with multiple ssh sessions
CSCwk05851"set ip next-hop" line deleted from config at reload if IP address is matched to a NAME
CSCwk06564Add New Syslog for Routes for NP add/delete
CSCwk07934Clock skew between FXOS and Lina causes SAML assertion processing failure
CSCwk08576command to print the debug menu setting of service worker
CSCwk09612Clock skew: FXOS clock diverges from Lina NTP time ~1-10 secs
CSCwk12497Traceback and reload on active unit due to HA break operation.
CSCwk12698SNMP polling of admin context mgmt interface fails to show all interfaces across all contexts
CSCwk12738Cisco Adaptive Security Virtual Appliance and Secure FTD Virtual SSL VPN DoS Vulnerability
CSCwk13631Traceback and reload during FTD upgrade due to FQDN network object NAT
CSCwk13812ASA/FTD incorrectly forwards extended community attribute after upgrade.
CSCwk14909Traffic drop with 'rule-transaction-in-progress' after failover with TCM cfgd in multi-ctx mode
CSCwk17637State Link Stops Sending Hello Messages Post-Failover Triggered by Snort traceback in FTD HA
CSCwk17854FTD doesn't send Type A query after receiving a refuse error from one DNS server in AAAA query.
CSCwk20882ESP sequence number of 0 being sent after SA establishment/rekey
CSCwk21561Add warning message when configuring CCL MTU
CSCwk22034Snmpwalk displays incorrect interface speeds for values greater or equal than 10G
CSCwk22759Issue with Setting Certain Timezones (e.g. GMT+1) on Cisco ASA Firepower in Appliance Mode
CSCwk25117ENH: Add application support for blocking consecutive AAA failures on LINA
CSCwk27830ASA/FTD may traceback and reload in Thread Name 'lina'
CSCwk32501256/1550 block depletion process fover_thread
CSCwk36312High cpu on "update block depletion" with secondary effects (Bgp flaps, traffic drops)
CSCwk44165Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability


Version 9.18.4.29 – June 6, 2024

Defects resolved in this release:

CSCvy51481[ENH] FTD should show error/warning when attaching a not valid certificate to the interface for VPN
CSCwb03293IKEv2 debugs: Received Policies and Expected Policies are empty
CSCwh29276ASA: Traceback and reload when switching from single to multiple mode
CSCwh60971NAT pool is not working properly despite is not reaching the 32k object ID limit.
CSCwh83021ASA/FTD HA pair EIGRP routes getting flushed after failover
CSCwi43492ASA traceback and reload on Thread Name: DATAPATH
CSCwi49770ASA|FTD Traceback & reload in thread name Datapath
CSCwi56499Cut-Through Proxy feature spikes CP CPU with a flood of un-authenticated traffic
CSCwi66461WARN msg(speed not compatible, suspended) while creating port-channel on Victoria CE
CSCwi95796FTD SNMP OID 1.3.6.1.4.1.9.9.109.1.1.1.1.7 always returns 0% for SysProc Average
CSCwj03764In Spoke dual ISP case if ISP2 is down, VTI tunnels related to ISP1 flapping.
CSCwj05151ASA/FTD may traceback and reload in Thread Name DATAPATH due to GTP Spin Lock Assertion
CSCwj08667ASA/FTD Traceback and Reload during ssl session establishment
CSCwj13910Crypto IPSEC SA Output Showing NO SA ERROR With IPSEC Offload Enabled
CSCwj19653FTD - Trace back and reload due to NAT involving fqdn objects
CSCwj22086Active unit goes to disabled state when there is a mismatch in firewall mode
CSCwj30980Addition of debugs & a show command to capture the ID usage in the CTS SXP flow.
CSCwj34881Command to show counters for access-policy filtered with a source IP address gives incorrect result
CSCwj34975Multiple context interfaces fail to pass traffic
CSCwj38871ASA traceback with thread name SSH
CSCwj44398when set the route-map in route RIP on FTD, routes update is not working after FTD reload
CSCwj48704ASA traceback and reload when accessing file system from ASDM
CSCwj49958Crypto IPSEC Negotiation Failing At "Failed to compute a hash value"
CSCwj50406All IPV6 BGP routes configured in device flapping
CSCwj55036ASA/FTD: A delay in an async crypto command induces a traceback and subsequently a reload.
CSCwj59861ASA/FTD may traceback and reload in Thread Name 'lina' due to SCP/SSH process
CSCwj60265ASA/FTD may traceback and reload in Thread Name 'DATAPATH-1-16803'
CSCwj62723Error message spammed to console on Firepower 2100 devices while enabling SSH config
CSCwj68096Console Access Stuck for ASAv hosted in CSP after Upgrade to 9.18.3.56
CSCwj68783FTD/ASA-HA configs not in sync as the command sync process is sending configs with special chars
CSCwj72683ASA - Bookmarks on the WebVPN portal are unreachable after successful login.
CSCwj73053ASA may traceback and reload in Thread Name 'DATAPATH-21-16432'
CSCwj76503Syslogs continue to be sent after disabling logging class on ASA
CSCwj82285ASA/FTD may traceback and reload in Thread Name 'sdi_work'
CSCwj86116High LINA CPU observed due to NetFlow configuration
CSCwj91570Cisco ASA and FTD Software Remote Access VPN Brute Force Denial of Service Vulnerability
CSCwj93921ASA after upgrade to 9.18.4.24 not able to save config with error: "Configuration line too long"
CSCwj95590Browser redirects to logon page when the user clicks the WebVPN bookmark


Version 9.18.4.24 – May 2, 2024

Defects resolved in this release:

CSCvz70310ASA may fail to create NAT rule for SNMP with: "error NAT unable to reserve ports."
CSCwc28334Cisco ASA and FTD Software RSA Private Key Leak Vulnerability
CSCwd67100ASA traceback and reload on Datapath process
CSCwe02012ASA/FTD may traceback and reload in Thread Name 'lina'
CSCwe18462ASA/FTD: Improve GTP Inspection Logging
CSCwe18467ASA/FTD: GTP Inspection engine serviceability
CSCwe21884Write wrapper around "kill" command to log who is calling it
CSCwf39108Firewall rings may get stuck and cause packet loss when asp load-balance per-packet auto is used
CSCwf69880Firewall Traceback and reload due to SNMP thread
CSCwf75694ASA - The GTP inspection dropped the message 'Delete PDP Context Response' due to an invalid TEID=0
CSCwf84318ASA/FTD traceback and reload on thread DATAPATH
CSCwh40294ASA traceback due to panic event during SNMP configuration
CSCwh454502100: Interfaces missing from FTD after removing interfaces as members of a port-channel
CSCwh68068Firepower WCCP router-id changes randomly when VRFs are configured
CSCwh69156FTD-HA does not fail over sometimes when snort3 traceback
CSCwh69843WM DT - ASA in transparent mode doesn't send equal IPv6 Router Advertisement packets to all nodes
CSCwh91065Lina Traceback : Thread Name: DATAPATH during session terminate
CSCwh92345crypto_archive file generated after the software upgrade.
CSCwh95025GTP connections, under certain circumstances do not get cleared on issuing clear conn.
CSCwh95277FTD traceback due to system memory exhaustion
CSCwh95443Datapath hogs causing clustering units to get kicked out of the cluster
CSCwh96055Management DNS Servers may be unreacheable if data interface is used as the gateway
CSCwh99398ASA/FTD may traceback and reload in Thread Name 'DATAPATH-34-17852'
CSCwi02754FTD 1120 Traceback and reload on standby unit with SNMP enabled.
CSCwi03407Traceback on FP2140 without any trigger point.
CSCwi04351FTD upgrade failling on script 999_finish/999_zz_install_bundle.sh
CSCwi06797ASA/FTD traceback and reload on thread DATAPATH
CSCwi20045ASA/FTD may traceback and reload in Thread Name 'lina' due to a watchdog (watchdog_time = 0)
CSCwi31966FTD ADI debugs may show incorrect server_group and/or realm_id for SAML-authenticated sessions
CSCwi36311use kill tree function in SMA instead of SIGTERM
CSCwi36843Detailed logging related to reason behind sub-interface admin state change during operations
CSCwi40193Hairpinning of DCE/RPC/FTP traffic during the suboptimal lookup
CSCwi42291Cisco Firepower Threat Defense Software TCP Snort 3 Detection Engine Bypass Vulnerability
CSCwi44208low memory/stress causing traceback in SNMP
CSCwi45878ASA/FTD: DNS Load Balancing with SAML does not work with VPN Load Balancing
CSCwi48699ASA traceback and reload on Thread Name: pix_flash_config_thread
CSCwi49884TCP MSS is changed back to the default value when a VTI or loopback interface is created
CSCwi53987SSL protocol settings does not modify the FDM GUI certificate configuration or disable TLSv1.1
CSCwi55938The "show asp drop" command usage requires better updates for cluster-related drops
CSCwi56667ASA Traceback and reload on Thread Name "fover_parse" on Standby after Failover Group changes
CSCwi60285ASA/FTD may traceback and reload in Thread Name 'lina'
CSCwi61135Debugs failed to be enabled on SSH session
CSCwi62796ASA/FTD Traceback and reload related to SSL/DTLS traffic processing
CSCwi63113Null pointer dereference in SNMP that results in traceback and reload
CSCwi63743ASA/FTD may traceback and reload in Thread Name "appAgent_monitor_nd_thread" & Rip: _lina_assert.
CSCwi64829traceback and reload around function HA
CSCwi65116DHCPv6:ASA traceback on Thread Name: DHCPv6 CLIENT.
CSCwi66676ASA/FTD may traceback and reload in Thread Name 'webvpn_task'
CSCwi68625Continuous snmpd restarts observed if SNMP host is configured before the IP is configured
CSCwi68833ASA/FTD: Memory leak caused by Failover not freeing dnscrypt key cache due to unsyned umbrella flow
CSCwi69091ASA/FTD may traceback and reload in Thread Name 'lina'
CSCwi70492Firewall is in App Sync error in pseudo-standby mode and uses IPs from Active unit
CSCwi71998"Stream: TCP normalization error in NO_TIMESTAMP" is seen when SSL Policy decrypt all is used
CSCwi74214ASA/FTD traceback and reload in Thread Name: IKEv2 Daemon when moving from active to standby HA
CSCwi75198Standby FTD experiencing periodic traceback and reload
CSCwi76361Transparent firewall MAC filter does not capture frames with STP-UplinkFast dst MAC consistently
CSCwi79037IKEv2 client services is not getting enabled - XML profile is not downloaded
CSCwi79042FTD/Lina traceback and reload of HA pairs, in data path, after adding NAT policy
CSCwi79393Policy Deployment Fails when removing the Umbrella DNS Policy from Security Intelligence
CSCwi80465CCM ID 63 - LTS18
CSCwi84314ASA CLI hangs with 'show run' on multiple SSH
CSCwi85689TLS Server Identify: 'show asp table socket' output shows multiple TLS_TRK entries
CSCwi87382Traceback and reload on Primary unit while running debugs over the SSH session
CSCwi90571Access to website via Clientless SSL VPN Fails
CSCwi90998ASA SNMP Polling Failure for environmental FXOS DME MIB (.1.3.6.1.4.1.9.9.826.2)
CSCwi95228"crypto ikev2 limit queue sa_init" resets after reboot
CSCwi95994Chromium-based browsers have SSL connection conflicts when FIPS CC is enabled on the firewall.
CSCwi96562Cisco ASA and FTD FXOS CLI Root Privilege Escalation Vulnerability
CSCwi97836ASA traceback and reload after configuring capture on nlp_int_tap and deleting context
CSCwi97839FTD traceback assert in vni_idb_get_mode and reloaded
CSCwi99429Policy deployment failure rollback didnt reconfigure the FTD devices
CSCwj02505ASA Checkheaps traceback while entering same engineID twice
CSCwj05484ASA upgrade from 9.16 to 9.18 causing change in AAA ldap attribute values by adding extra slash '\'
CSCwj06675Cisco ASA and FTD Software Persistent Local Code Execution Vulnerability
CSCwj09110Upload files through Clientless portal is not working as expected after the ASA upgrade
CSCwj09999FP 3100 MTU change on management interface is NOT persistent across reboots (returns to default MTU)
CSCwj10451The secondary device reloaded while rebooting the primary device.
CSCwj14028CCM ID 67 - LTS18
CSCwj14832SAML: Single sign-on AnyConnect token verification failure is seen after successful authentication
CSCwj15792Cisco ASA and FTD Software Dynamic Access Policies Denial of Service Vulnerability
CSCwj16125Traceback and Reload when testing or loading an invalid hostscan image
CSCwj17447ASA/FTD may traceback and reload in Thread Name 'DATAPATH-6-26174'
CSCwj20067ASA: Warning messages not displayed when Static interface NAT are configured
CSCwj21880FTD with Interface object optimization enabled is blocking traffic after renaming of zone names
CSCwj22235Lina traceback and reload due to mps_hash_memory pointing to null hash table
CSCwj22990After upgrading the ASA, \u201cSlot 1: ATA Compact Flash memory\u201d shows a ditterent value
CSCwj25975FTD/ASA : CSR generation with comma between \u201cCompany Name\u201d attribute does not work expected
CSCwj32035Clientless VPN users are unable to reach pages with HTTP Basic Authentication
CSCwj33487ASA/FTD may traceback and reload while handling DTLS traffic
CSCwj33580IKEv2 tunnels flap due to fragmentation and throttling caused by multiple ciphers/proposal
CSCwj33891ASA/FTD Cluster memory exhaustion caused by NAT process during release of port blocks allocations
CSCwj38928High latency observed on FPR31xx
CSCwj40761ASA/FTD may traceback in Threadname: **CTM KC FPGA stats handler**


Version 9.18.4.22 – March 6, 2024

Defects resolved in this release:

CSCvx37329Remove Syslog Messages 852001 and 852002 in Firewall Threat Defense
CSCwc31953Prevention of RSA private key leaks regardless of root cause.
CSCwe47485FTD: CLISH slowness due to command execution locking LINA prompt
CSCwe72330FTD LINA traceback and reload in Datapath thread after adding Static Routing
CSCwe93736ASA not updating Timezone despite taking commands
CSCwe97939ASA/FTD Cluster: Change "cluster replication delay" with max value increase from 15 to 50 sec
CSCwf11877TPK 3110 - Firmware version MISMATCH after upgrade to 7.2.4-144
CSCwf34070Cisco ASA and FTD Remote Access SSL VPN Authentication Targeted Denial of Service Vulnerability
CSCwf36419ASA/FTD: Traceback and reload with Thread Name 'PTHREAD'
CSCwf82279Excessive logging of ssp-multi-instance-mode messages to /opt/cisco/platform/logs/messages
CSCwf87348When state-link is flapped HA state changed from Standby-ready to Bulk-sync without failover reason
CSCwf99303Management UI presents self-signed cert rather than custom CA signed one after upgrade
CSCwh16759SNMP is not working on the primary active ASA unit in multi-context environment
CSCwh17576Site-to-Site VPN tunnel status on FMC shows down even though it is UP from FTD side
CSCwh19352comm alarm is raised and unit switches over even if one ack is dropped.
CSCwh43945FTD/ASA traceback and reload may occur when ssl packet debugs are enabled
CSCwh47053ASA/FTD may traceback and reload in Thread Name 'dns_cache_timer'
CSCwh58467ASA does not sent 'warmstart' snmp trap
CSCwh62731FTD Upgrade from 6.6.5 to 7.2.5 removing OGS causing rule expansion on boot
CSCwh65128LINA show tech-support fails to generate as part of sf_troubleshoot.pl (Troubleshoot file)
CSCwh66636Configuring and unconfiguring "match ip address test" may lead to traceback
CSCwh69346ASA: Traceback and reload when restore configuration using CLI
CSCwh71161ASA|FTD: Traceback & reload in thread Name: update_mem_reference
CSCwh71589Coverity 886745: OVERRUN in verify_generic_signature
CSCwh83254ASA/FTD: Traceback and reload on thread name CP Crypto Result Processing
CSCwh84376In FPR4200/FPR3100-HA/cluster observed crashinfo/corefile.lina observed on device reboot.
CSCwh91574FTD: Traceback in threadname cli_xml_request_process
CSCwh93710'Last Hit' Timestamp fails to Update to latest value on ASA, ASDM, and FTD
CSCwh95010Unexpected traceback on thread name Lina and device experienced reboot
CSCwi01085FTD VMWare tracebacks at PTHREAD-3587
CSCwi01381ASA/FTD may traceback and reload in Thread Name 'lina'
CSCwi02134FTD sends multiple replicated NetFlow records for the same flow event
CSCwi02919SNMP Unresponsive when snmp-server host specified
CSCwi03528Cross ifc access: Revert PING to old non-cross ifc behavior
CSCwi06690Certificate Encoding Issue when using AnyConnect cert Authentication/Authorisation
CSCwi11520FTD OSPFV3 IPV6 Routing: FTD is sending unsupported extended LSA request to neighbor routers
CSCwi12284Cisco ASA webvpn XSS Vulnerability
CSCwi12772ASA cluster traceback Thread Name: DATAPATH-8-17824
CSCwi13134Hardware bypass not working as expected in FP3140
CSCwi15409ASA/FTD - may traceback and reload in Thread Name 'Unicorn Proxy Thread'
CSCwi18581Firewall traceback and reload due to SSH thread
CSCwi19015ASA/FTD may traceback and reload in Thread Name 'DATAPATH-13-6022'
CSCwi19145FTD/ASA may traceback and reload in PKI, syslog, during upgrade
CSCwi19849VPN load-balancing cluster encryption using Phase 2 deprecated ciphers
CSCwi20114Cisco ASA Software and FTD Software SNMP Denial of Service Vulnerability
CSCwi20848ASA/FTD high memory usage due to SNMP caused by RAVPN OID polling
CSCwi20955FTD with may traceback in data-path during deployment when enabling TAP mode
CSCwi21625FailSafe admin password is not properly sync'd with system context enable pw
CSCwi22296ASA: The logical device may boot into failsafe mode because of an large configuration.
CSCwi24461Device/port-channel goes down with a core generated for portmanager
CSCwi24880ASA dropping IPSEC traffic incorrectly when "ip verify reverse-path" is configured
CSCwi26064ASA : Modifying a route-map in one context affects other contexts
CSCwi26895ASA SNMP OID cpmCPUTotalPhysicalIndex returning zero values instead of CPU index values
CSCwi27338Stale asp entry for TCP 443 remains on standby after changing default port
CSCwi29532ASA/FTD traceback and reload due to sigcrash in inspect_dp_pdts_recv_service_producer_vec
CSCwi31091OSPF Redistribution route-map with prefix-list not working after upgrade
CSCwi31766PSU fan shows critical in show environment output while operating normally
CSCwi32063ASA/FTD: SSL VPN Second Factor Fields Disappear
CSCwi32759Username-from-certificate secondary attribute is not extracted if the first attribute is missing
CSCwi34125ASA: Snmpwalk shows "No Such Instance" for the OID ceSensorExtThresholdValue
CSCwi35267TLS1.3: core decode points to tls_trk_try_switch_to_bypass_aux()
CSCwi38957Policy Apply failed moving from FDM to FMC
CSCwi40536ASA/FTD: Traceback and reload when running show tech and under High Memory utilization condition
CSCwi42295Radius traffic not passing after ASA upgrade 9.18.2 and above version.
CSCwi42992ASA/FTD may traceback and reload in Thread Name IKEv2 Daemon
CSCwi43782GTP inspection dropping packets with IE 152 due to header length being invalid for IE type 152
CSCwi45630Snort3 traceback with fqdn traffics
CSCwi46010ASA/FTD: Cluster incorrectly generating syslog 202010 for invalid packets destined to PAT IP
CSCwi46023FTD drops double tagged BPDUs.
CSCwi46641FTDv may traceback and reload in Thread Name 'PTHREAD-3744' when changing interface status
CSCwi50343Their standalone FTD running 7.2.2 on FPR-4112 experienced a traceback on the SNMP module
CSCwi53150Service object-group protocol type mismatch error seen while access-list referencing already
CSCwi53431Unable to Synch more then 100 environment-data with data unit
CSCwi56048Interface fragment queue may get stuck at 2/3 of fragment database size
CSCwi59525Multiple lina cores on 7.2.6 KP2110 managed by cdFMC
CSCwi59831ASA/FTD may traceback and reload in Thread Name 'lina'
CSCwi62683The SSH transport protocol with certain OpenSSH extensions, found in ... (CVE-2023-48795)
CSCwi76002Memory exhaustion due to absence of freeing up mechanism for tmatch
CSCwi76630FP2100/FP1000: ASA Smart licenses lost after reload
CSCwi79703Incorrect Timezone Format on FTD When Configured via FXOS
CSCwi80465CCM ID 63 - LTS18
CSCwi90040Cisco ASA and FTD Software Command Injection Vulnerability
CSCwi90399FTD/ASA system clock resets to year 2023
CSCwi95708FTD: Hostname Missing from Syslog Message
CSCwi98284Cisco ASA and FTD Software Persistent Local Code Execution Vulnerability
CSCwj10955Cisco ASA and FTD Software Web Services Denial of Service Vulnerability


Version 9.18.4.8 – November 29, 2023

Defects resolved in this release:

CSCvx44261SNMPv3: Special characters used in FXOS SNMPv3 configuration causes authentication errors
CSCwd31806ASAv show crashinfo printing in loop continuously
CSCwf43850ECMP + NAT for ipsec sessions support request for Firepower.
CSCwf89959ASA: ISA3000 does not respond to entPhySensorValue OID SNMP polls
CSCwf92661ASA|FTD: Traceback & reload due to a free buffer corruption
CSCwh14863FTD 7.0.4 cluster drops Oracle's sqlnet packets due to tcp-not-syn
CSCwh18967Include "show env tech" in FXOS FPRM troubleshoot
CSCwh30346ASA/FTD: 1 Second failover delay for each NLP NAT rule
CSCwh54477The FMC is showing "The password encryption key has not been set" alert for a 11xx/21xx/31xx device
CSCwh60631Fragmented UDP packet via MPLS tunnel reassemble fail
CSCwh66359ASDM can not see log timestamp after enable logging timestamp on cli
CSCwh68482Cisco Firepower Threat Defense Software for Firepower 2100 Series TLS Denial of Service Vu
CSCwh70323Timestamp entry missing for some syslog messages sent to syslog server
CSCwh70481Community string sent from router is not matching ASA
CSCwh71665ASA traceback under match_partial_keyword during CPU profiling
CSCwh77348ASA: Traceback and reload when executing the command "show nat pool detail" on a cluster setup
CSCwh93649File copy via SCP using ciscossh stack fails with error "no such file or directory"
CSCwh95175ASA/FTD may traceback and reload in Thread Name 'lina'
CSCwi15595ASA traceback and reload during ACL configuration modification


Version 9.18.4.5 – October 25, 2023

Defects resolved in this release:

CSCwc78781 ASA/FTD may traceback and reload during ACL changes linked to PBR config
CSCwd34079 FTD: Traceback & reload in process name lina
CSCwe28912 Primary Unit lost all HA config after FTD HA upgrade
CSCwe44099 Cisco Adaptive Security Virtual Appliance and Secure FTD Virtual SSL VPN DoS Vulnerability
CSCwf36621 access-list: Cannot mix different types of access lists.
CSCwf41433 ASA/FTD client IP missing from TACACS+ request in SSH authentication
CSCwf63589 FTD snmpd process traceback and restart
CSCwf64590 Units get kicked out of the cluster randomly due to HB miss | ASA 9.16.3.220
CSCwf69901 FTD: Traceback and reload during OSPF redistribution process execution
CSCwf94450 FTD Lina traceback Thread Name: DATAPATH due to memory corruption
CSCwf95288 FPR1k Switchport passing CDP traffic
CSCwh09113 FPR1010 in HA failed to send or receive to GARP/ARP with error "edsa_rcv: out_drop"
CSCwh14352 Lina CiscoSSL upgrade to 1.1.1v and FOM 7.3a
CSCwh16301 Incorrect Hit count statistics on ASA Cluster only for Cluster-wide output
CSCwh19897 ASA/FTD Cluster: Reuse of TCP Randomized Sequence number on two different conns with same 5 tuple
CSCwh21474 ASA traceback when re-configuring access-list
CSCwh32118 ASDM management-sessions quota reached due to HTTP sessions stuck in CLOSE_WAIT
CSCwh40106 FTD hosted on KP incorrectly dropping decoded ESP packets if pre-filter action is analyze
CSCwh42412 FTD Block 9344 leak due to fragmented GRE traffic over inline-set interface inner-flow processing
CSCwh47701 ASA allows same BGP Dynamic routing process for Physical Data and management-only interfaces
CSCwh48844 FTD: Failover/High Availability disabled with Mate version 0.0 is not compatible
CSCwh49244 "show aaa-server" command always shows the Average round trip time 0ms.
CSCwh53143 ASA:Management access via IPSec tunnel is NOT working
CSCwh53745 ASA: unexpected logs for initiating inbound connection for DNS query response
CSCwh59199 ASA/FTD traceback and reload with IPSec VPN, possibly involving upgrade
CSCwh59557 Source NAT Rule performing incorrect translation due to interface overload
CSCwh60604 ASA/FTD may traceback and reload in Thread Name 'lina' while processing DAP data
CSCwh60778 FTD traceback and reload within TLS tracker for TLS 1.3 SSL decryption
CSCwh63588 FTD SNMPv3 host configuration gets deleted from IPTABLES after adding host-group configuration
CSCwh70905 Secondary lost failover communication on Inside, using IPv6, but next testing of Inside passes


Last edited on: August 25, 2025