Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 8.6.1(17) – 04/08/2015

Files:  asa861-17-smp-k8.bin

Defects resolved since 8.6.1(15):

 

CSCts62187

Safari Browser crashes when accessing SmartTunnel link in Mac OS 10.7

CSCty36675

Smarttunneled RDP client on MAC doesn't throw error after incorrect auth

CSCud08385

Smart Tunnel failed for Safari 6.0.1/6.0.2 on OSX10.7 and 10.8

CSCue33354

Mac version Smart Tunnel with Safari 6.0.1/6.0.2 issue

CSCug51375

ASA SSL: Continues to accept SSLv3 during TLSv1 only mode

CSCui66657

Safari crashes when use scroll in safari on MAC 10.8 with smart-tunnel

CSCum26963

Webvpn: Add permissions attribute to mac smart-tunnel jar

CSCuq77655

1550 block leak occur if DNS replies "refused" query response

CSCur21069

Failover units should accept only traffic coming from the peer

CSCur23709

ASA  : evaluation of SSLv3 POODLE vulnerability

CSCur42776

Mac version smart-tunnel uses SSLv3 which is  a vulnerability

CSCus08101

ASA: evaluation of Poodle Bites in TLSv1

CSCus42901

JANUARY 2015 OpenSSL Vulnerabilities

CSCus95290

ASA / denial of service against xml parser.

CSCut45114

2048-byte block leak if DNS server replies with "No such name"

 

 

Revision:  Version 8.6.1(15) – 10/08/2014

Files:  asa861-15-smp-k8.bin

Defects resolved since 8.6.1(14):

 

CSCuq28582

Cisco ASA Privilege Escalation

CSCuq29136

ASA: Entering Query String on /+CSCOE+/logon.html disclose information

 

 

Revision:  Version 8.6.1(14) – 07/28/2014

Files:  asa861-14-smp-k8.bin

Defects resolved since 8.6.1(13):

 

CSCum46027

Cisco ASA SQL*NET Inspection Engine Denial of Service Vulnerability

CSCum96401

Cisco ASA IKEv2 Denial of Service Vulnerability

CSCun10916

Cisco ASA SCH Digital Certificate Validation Vulnerability

CSCun11074

ASA:Tracebacks in thread dispatch unit due to SunRPC inspection

CSCup22532

Multiple Vulnerabilities in OpenSSL - June 2014

CSCup36829

ASA WebVPN portal modification vulnerability

 

 

Revision:  Version 8.6.1(13) – 04/09/2014

Files:  asa861-13-smp-k8.bin

Defects resolved since 8.6.1(12):

 

CSCua85555

Cookie usage in SSL VPN

CSCub38407

Add text section to coredump

CSCuh44052

ASA sip inspection memory leak

CSCuj33496

Privillage level 0 users getting full access

CSCul70099

ASA SSL VPN Privilege Escalation Vulnerability

CSCum00556

Page fault traceback in DATAPATH under DoS, rip qos_topn_hosts_db_reset

 

 

Revision:  Version 8.6.1(12) – 10/09/2013

Files:  asa861-12-smp-k8.bin

Defects resolved since 8.6.1(10):

 

CSCtf79704

ASA -crasActGrNumUsers does not update tunnel groups after upgrade

CSCtg58074

ASA CRYPTO: Hardware Accelerator Archive File Created

CSCua22709

ASA traceback in Unicorn Proxy Thread while processing lua

CSCub98434

ASA - SQL*Net Inspection Engine Denial of Service Vulnerability

CSCuc65775

ASA CIFS UNC Input Validation Issue

CSCuc66227

Port-channel config fails, Error: unable to get MCAST_MAC_TABLE_SIZE

CSCud37992

HTTP Deep Packet Inspection Denial of Service Vulnerability

CSCuf29783

ASA traceback in Thread Name: ci/console after write erase command

CSCug03975

ASA DNS Inspection Denial of Service Vulnerability

CSCug34469

ASA OSPF LSA Injection Vulnerability

CSCug83401

ASA Remote Access VPN Authentication Bypass Vulnerability

CSCuh44815

ASA Digital Certificate HTTP Authentication Bypass Vulnerability

 

 

Revision:  Version 8.6.1(10) – 03/13/2013

Files:  asa861-10-smp-k8.bin

Defects resolved since 8.6.1(5):

 

CSCtj87870

Failover disabled due to license incompatible different Licensed cores

CSCtn56517

"Failed to update IPSec failover runtime data" msg on the standby unit

CSCtr38739

Link outage in Etherchannel causes interface down and failover

CSCts50584

ASA may reload with traceback in Thread Name scmd reader thread

CSCts69531

Traceback in Dispatch Unit on Standby with timeout floating-conn

CSCts98806

Standby ASA 5585 Reporting Service Card Failure on Signature Update

CSCtt07749

ASA is responding to IKE request when in vpnclient mode

CSCtt11890

ASA: Manual NAT rules inserted above others may fail to match traffic

CSCtt18185

ASA traceback cause by Global Policy

CSCtt19760

ASA may traceback in a DATAPATH thread

CSCtt74695

wrong vpn-filter gets applied when peers have overlapping address space

CSCtu07278

Corrupted route-map output for 'config' URL used by ASDM

CSCtv19854

Incorrect MPF conn counts cause %ASA-3-201011 and DoS condition for user

CSCtw56707

%ASA-3-201011: Connection limit exceeded when not hitting value

CSCtw59136

ASA: 8.3+ NAT overlap with failover IP cause both units to go active

CSCtw82147

ASA lets static NAT mapped IP to be same as standby address on interface

CSCtx62037

"X-CSTP-Tunnel-All-DNS" not properly set in SMP images for split-dns

CSCty16864

ASA doesn't start quick mode negotiation - stuck tunnel manager entries

CSCtz11129

ASA Radius Acct-Delay-Time does not work

CSCtz31686

SNMP ciscoRasTooManySessions trap is sent from Standby ASA

CSCtz71022

(VPN-Secondary) Failed to update IPSec failover runtime data on the stan

CSCua61119

ASA: Page fault traceback when changing port-channel load balancing

CSCua68934

ASA: May log 305006 regular translation creation failed messages.

CSCua87170

Interface oversubscription on active causes standby to disable failover

CSCua91189

Traceback in CP Processing when enabling H323 Debug

CSCua93764

ASA: Watchdog traceback from tmatch_element_release_actual

CSCua99091

ASA: Page fault traceback when copying new image to flash

CSCub16427

Standby ASA traceback while replicating flow from Active

CSCub23840

ASA traceback due to nested protocol object-group used in ACL

CSCub40805

After some time "show inventory" fails to display Power Supply SN

CSCub59536

NAT Config Rejected on Upgrade when Objects Overlap with Failover IP

CSCub70946

ASA traceback under threadname Dispatch Unit due to multicast traffic

CSCub72990

ASA is max-aging OSPF LSAs after 50 minutes

 

CSCub85692

ASA traceback in IKE Daemon while handling IKEv1 message

 

CSCuc04636

Traceback in Thread Name: accept/http

CSCuc06857

Accounting STOP with caller ID 0.0.0.0 if admin session exits abnormally

CSCuc12967

OSPF routes were missing on the Standby Firewall after the failover

CSCuc24547

TCP ts_val for an ACK packet sent by ASA for OOO packets is incorrect

CSCuc28903

ASA 8.4.4.6 and higher: no OSPF adj can be build with Portchannel port

CSCuc56078

Traceback in threadname CP Processing

 

CSCuc72408

ASA 5580 page fault in thread CERT API during pki validation

 

CSCuc75093

Log indicating syslog connectivity not created when server goes up/down

CSCud16590

ASA may traceback in thread emweb/https

 

CSCud89974

flash in ASA5505 got corrupted

 

CSCue99041

Smart Call Home sends Environmental message every 5 seconds for 5500-X

 

 

Revision:  Version 8.6.1(5) – 09/18/2012

Files:  asa861-5-smp-k8.bin

Defects resolved since 8.6.1(2):

 

CSCsw31922

Radius upstream VSAs (Tunnel Group,Client type) for VPN policy decisions

CSCtq57752

ASA: IPSec outbound SA data lifetime rekey fails

CSCtq78280

invalid command dhcp client xxx on ASA 8.4

CSCtr24705

Traceback seen while running packet-tracer due to Page fault

CSCtr63728

ASA reloads with traceback in Thread Name : Dispatch Unit

CSCtr85499

ASA: Radius MS-CHAPV2 with challenge fails

CSCts15920

ASA: WCCP with authentication fails in 8.3 and 8.4

CSCts30839

ASA5510, 8.4(2) - page fault traceback accessing a bookmarked DFS share

CSCts50723

ASA: Builds conn for packets not destined to ASA's MAC in port-channel

CSCtt02413

DCERPC inspection does not properly fix up port and IP in Map Response

CSCtt29654

Outbound IPsec traffic interruption after successful Phase2 rekey

CSCtt36737

After upgrade, AnyConnect causes 1550 or 2048 block depletion

CSCtt96526

SharePoint2010:Cannot create new document

CSCtt98991

ASA: Decrypted VPN packets dropped due to bad-tcp-cksum when using NAT-T

CSCtx25170

Configuring a network object with an invalid range causes traceback

CSCtx43083

Syslog 199011 "Close on bad channel in process/fiber"

CSCtx92801

ASA: Failover due to data channel failure when making IPS config changes

CSCty95468

ENH: Add Command to Allow ARP Cache Entries from Non-Connected Subnets

CSCty95742

ASA-4-402116 - error message displays outer instead of inner packet

CSCtz63143

ASA sip inspect - duplicate pre-allocate secondary pinholes created

CSCtz94894

ASA: CPU profile activate command prints incorrect instructions

CSCtz97792

Block depletion, embedded web client transmit queue

CSCua20850

5500X Software IPS console too busy for irq can cause data plane down.

CSCua22249

auto-nego results in 100MB on ASA5500-X Giga interfaces

CSCua27134

Traceback in Thread Name: Dispatch Unit

CSCua45611

pki: import from terminal fails when 'quit' embedded in certificate

CSCua82297

ASA 5500-x only show 4096MB flash in 'show ver'

CSCua95621

ASA:write standby command brings down port-channel interface on standby

CSCub07976

config factory-default does not clear ssl commands

 

 

Revision:  Version 8.6.1(2) – 06/11/2012

Files:  asa861-2-smp-k8.bin

Defects resolved since 8.6.1(1):

 

CSCtn56501

ASA 8.2 Crypto Engine Tracebacks Multiple Times

CSCts00158

ASA EIGRP route not updated after failover

CSCts45638

8.4.2.2: Thread Name: DATAPATH-0-1272 Page fault: Unknown

CSCtt22540

Secondary Auth successfully connects with blank password

CSCtt41809

ASASM traceback in DATAPATH-3-2265

CSCtt96550

ASA - Dispatch unit traceback - snp_nat_xlate_timeout

CSCtu30581

ASA 5580 traceback when CSM attempts deployment

CSCtw84087

IKEv2: ASA does not re-establish more than one SA after disconnect

CSCty37057

ASA crash causes reloads when removing stale SunRPC action hole

CSCtz56314

ASA5500-X Chassis Serial Number Not Visible from CLI

CSCtz73669

ASA5515 doesn't support "config factory-default"

 

 

Revision:  Version 8.6.1(1) – 03/14/2012

Files:  asa861-1-smp-k8.bin

Defects resolved since 8.6.1:

 

CSCtr00165

Port Forwarder ActiveX control contains a Buffer Overflow vulnerability

CSCtu33381

Clientless Port Forward control may cause an unhandled C++ exception

CSCtw35765

Threat Detection Denial Of Service Vulnerability

CSCtx58556

ActiveX RDP Plugin fails to connect from WIn7 PC after upgrade to 8.4(3)

CSCty31392

RDP activex portforwarder is sometimes not loading