Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 8.5.1(24) – 04/08/2015

Files:  asa851-24-smp-k8.bin

Defects resolved since 8.5.1(22):

 

CSCug51375

ASA SSL: Continues to accept SSLv3 during TLSv1 only mode

CSCup22532

Multiple Vulnerabilities in OpenSSL - June 2014

CSCuq77655

1550 block leak occur if DNS replies "refused" query response

CSCur21069

Failover units should accept only traffic coming from the peer

CSCur23709

ASA  : evaluation of SSLv3 POODLE vulnerability

CSCus42901

JANUARY 2015 OpenSSL Vulnerabilities

CSCut45114

2048-byte block leak if DNS server replies with "No such name"

 

 

Revision:  Version 8.5.1(22) – 10/08/2014

Files:  asa851-22-smp-k8.bin

Defects resolved since 8.5.1(21):

 

CSCuq28582

Cisco ASA VPN Failover Commands Injection Vulnerability

 

 

Revision:  Version 8.5.1(21) – 07/28/2014

Files:  asa851-21-smp-k8.bin

Defects resolved since 8.5.1(19):

 

CSCua51319

simultaneous config-changes on multiple contexts can't be synchronized

CSCui63001

ASA traceback in Thread Name: fover_parse during command replication

CSCun11074

ASA:Tracebacks in thread dispatch unit due to SunRPC inspection

 

 

Revision:  Version 8.5.1(19) – 04/09/2014

Files:  asa851-19-smp-k8.bin

Defects resolved since 8.5.1(18):

 

CSCtr00165

Port Forwarder ActiveX control contains a Buffer Overflow vulnerability

CSCua85555

Cookie usage in SSL VPN

CSCub38407

Add text section to coredump

CSCum00556

Page fault traceback in DATAPATH under DoS, rip qos_topn_hosts_db_reset

 

 

Revision:  Version 8.5.1(18) – 10/09/2013

Files:  asa851-18-smp-k8.bin

Defects resolved since 8.5.1(17):

 

CSCub98434

ASA - SQL*Net Inspection Engine Denial of Service Vulnerability

CSCud16590

ASA may traceback in thread emweb/https

CSCud37992

HTTP Deep Packet Inspection Denial of Service Vulnerability

CSCue34342

ASA may traceback due to watchdog timer while getting mapped address

CSCug03975

ASA DNS Inspection Denial of Service Vulnerability

CSCug34469

ASA OSPF LSA Injection Vulnerability

CSCuh44815

ASA Digital Certificate HTTP Authentication Bypass Vulnerability

 

 

Revision:  Version 8.5.1(17) – 02/19/2013

Files:  asa851-17-smp-k8.bin

Defects resolved since 8.5.1(14):

 

CSCtf51346

ASA may leave connection in half-closed state

CSCtj68732

ASA: DHCP-Relay should forward out interface based on internal gi-addr

CSCtj87870

Failover disabled due to license incompatible different Licensed cores

CSCty62368

Traceback with Netflow configuration

CSCtz70573

SMP ASA traceback on periodic_handler for inspecting icmp or dns trafic

CSCua61119

ASA: Page fault traceback when changing port-channel load balancing

CSCua87170

Interface oversubscription on active causes standby to disable failover

CSCua91189

Traceback in CP Processing when enabling H323 Debug

CSCua99091

ASA: Page fault traceback when copying new image to flash

CSCub14196

FIFO queue oversubscription drops packets to free RX Rings

CSCub15394

unexpected policy-map is added on standby ASA when new context is made

CSCub16427

Standby ASA traceback while replicating flow from Active

CSCub70946

ASA traceback under threadname Dispatch Unit due to multicast traffic

CSCuc04636

Traceback in Thread Name: accept/http

CSCuc12967

OSPF routes were missing on the Standby Firewall after the failover

CSCuc24547

TCP ts_val for an ACK packet sent by ASA for OOO packets is incorrect

CSCuc34345

Multi-Mode traceback on ci/console copying config tftp to running-config

CSCuc63592

HTTP inspection matches incorrect line when using header host regex

 

CSCuc72408

ASA 5580 page fault in thread CERT API during pki validation

 

CSCuc78176

Cat6000/15.1(1)SY- ASASM/8.5(1.14) PwrDwn due to SW Version Mismatch

CSCuc83828

ASA Logging command submits invalid characters as port zero

CSCuc96911

ASASM platform is not exempt from MAC move wait timer

CSCud29045

ASASM forwards subnet directed bcast back onto that subnet

CSCud67282

data-path: ASA-SM: 8.5.1 traceback in Thread Name: SSH

 

 

 

 

Revision:  Version 8.5.1(14) – 10/02/2012

Files:  asa851-14-smp-k8.bin

Defects resolved since 8.5.1(7):

 

Note:  If your Supervisor card is running version 15.1(1)SY,  you should not use 8.5(1)14 for the ASA-SM.  Due to CSCuc78176  15.1(1)SY/8.5(1)14 - WS-SVC-ASA-SM1 "PwrDown" due to SUP_LINE_CARD_COMPATIBILITY-6-SW_VERSION_MISMATCH, the ASA-SM will be shut down by the supervisor card.  We recommend that you use ASASM 8.5(1)15 (target post date is early November).  8.5.1.14 will work fine with supervisor release 15.1(1)SY1 when it becomes available.

 

CSCtf79704

ASA -crasActGrNumUsers does not update tunnel groups after upgrade

CSCti16586

ASA 8.2(1)11 failed to return MIB data for SNMPV3 GetBulk request

CSCtj45148

ASA 8.3 upgrade traceback in thread pix_flash_config_thread

CSCtk93754

Change in Layered Object Group Does Not Update NAT Table

CSCtk97719

WebVPN & ASDM doesn't work on Chrome with AES & 3DES ciphers

CSCtl70594

SNMP: ifOutQLen gives free blocks instead of used blocks in ACMilan

CSCtn40707

assert traceback for ifc cfg removal with same-security intra-interface

CSCtn41118

ASA fails over under intensive single-flow traffic

CSCto73569

ASA WebVPN clientless not possible to access ipv6 services on the inside

CSCtq42954

ASA calculates ACL hash inorrectly

CSCtr00315

Active SSH connection orphaned if 'clear config all' is run

CSCtr23854

traceback in Crypto CA during multiple ocsp requests

CSCtr24705

Traceback seen while running packet-tracer due to Page fault

CSCtr26724

ASA threat detection does not show multicast sender IP in statistics

CSCtr35503

IPV6 router advertisements dropped by multicontext firewall

CSCtr38739

Link outage in Etherchannel causes interface down and failover

CSCtr79885

ASA with VoIP memory leak 1% per day on binsize 56

CSCtr83349

ASA logs "INVALID_NICNUM" messages to console

CSCtr93804

DCERPC inspection for RCI message type broken

CSCts07650

Traceback in  "clear config all" when  active telnet connection exists

CSCts16081

ASA Multicontext: allocated interface may not be configurable in context

CSCts50584

ASA may reload with traceback in Thread Name scmd reader thread

CSCts54522

Inspect PPTP does not change CALL-id for inbound Set-Link-Info Packet

CSCts72188

ASA: SSH process may exist after being orphaned from SSH session

CSCts89806

'Route-Lookup' Option Should be Allowed if One Real Interface is Known

CSCtt11890

ASA: Manual NAT rules inserted above others may fail to match traffic

CSCtt98033

Allow Concurrency of  'Unidirectional' and 'No-Proxy-Arp' Keywords

CSCtu03117

npshim: Shared License Registration Fails w/ Empty TP applied to Int

CSCtu04754

ASA may traceback citing Thread Name: qos_metric_daemon as culprit

CSCtu30581

ASA 5580 traceback when CSM attempts deployment

CSCtu51799

Traceback in Thread Name: CP Processing

CSCtu57453

ASA: Traceback after removing 'ip address dhcp setroute' with DDNS

CSCtu95699

ASA: Traceback with Checkheaps related to GTP inspection

CSCtv00813

ASA NAT fails to due route look with any as destination interface

CSCtv19854

Incorrect MPF conn counts cause %ASA-3-201011 and DoS condition for user

CSCtw45576

TCP sequence space check ignored in some cases

CSCtw55462

Traceback: assert failure on thread radius_snd

CSCtw60220

Port Address Translation (PAT) causes higher CPU after upgrade

CSCtw63996

Page fault traceback with thread name "pix_flash_config_thread".

CSCtw71420

ASA 5585-X does not provide aggregate system CPU load value via SNMP

CSCtw78415

ASA may reload with traceback in Dispatch Unit related to WAAS inspect

CSCtw84249

ASA 8.4 Email Proxy causes corruption of some email attachments

CSCtw93059

Page fault traceback in crypto_lib_keypair_show_mypubkey_all

CSCtx01251

ASA: May traceback in DATAPATH during capture

CSCtx02122

Post request for OCSP using non default port is missing the port number

CSCtx08182

 Nas-Port attribute different for authentication and accounting

CSCtx20103

ASA-SM requires ability to change default password in system context

CSCtx25170

Configuring a network object with an invalid range causes traceback

CSCtx33347

Standby ASA traceback while trying to replicate xlates

CSCtx33853

TCP Proxy TCP Window Size Update gets delayed

CSCtx42746

cut through proxy authentication vulnerability

CSCtx55814

Newly Added Failover Unit With Lesser License Rejects Configuration

CSCtx57829

Syslog 324001 Reason string is missing

CSCtx59946

ASA-SM may traceback in Thread Dispatch Unit

CSCtx65353

ASA: 8.4 Page fault traceback while displaying "sh run threat-detection"

CSCtx66538

ASA: Traceback in thread name EAPoUDP

CSCtx69498

Traceback when Converting ACL Remarks of 100 Characters

CSCtx81792

ASA: OSPF redist with prefix routemap advertises all static after reboot

CSCtx82637

tcp-proxy with skinny v17 inspection not allowing 7962 phone to register

CSCtx98402

ASA Multicontext with shared port-channel interface shutdown error

CSCtx98905

ASA traceback with Thread Name: dhcp_daemon

CSCty02513

Standby ASA remains standby after active ASA fails

CSCty07416

Migration of max_conn/em_limit to MPF is not working for dynamic NAT

CSCty12813

ASA 5585: Traceback after Reload when TCP syslog server unavailable

CSCty13927

ASA: Traceback in ldap_client_thread after changing aaa-server config

CSCty16661

ASA fails to reserve some UDP ports for PAT w/ flow-export destination

CSCty36034

ASA: Active/Active failover group stuck in Bulk Sync with SIP inspect

CSCty41149

Failover Cluster License Must be Cleared When Failover is Unconfigured

CSCty45900

NAT rules specifying an interface of any removed if an interface deleted

CSCty47140

New Create PDP Ctx Req with TEID 0 should remove pre-existing active PDP

CSCty95468

ENH: Add Command to Allow ARP Cache Entries from Non-Connected Subnets

CSCtz05457

authentication in esmtp inspection breaks

CSCtz12435

ASA - dhcp relay - option 252 is not passed down to the clients

CSCtz32065

Traceback in Thread Name accept/http

CSCtz40094

ASA 8.2.5.27 secondary traceback after the upgrade - Thread Name: snmp

CSCtz41928

Traceback: timer assert due to nf_block timer race condition

CSCtz63143

ASA sip inspect - duplicate pre-allocate secondary pinholes created

CSCtz79983

Incorrect MPF conn counts cause %ASA-3-201011 and DoS condition

CSCtz80888

ASDM Session Replication during Failover

CSCtz94894

ASA: CPU profile activate command prints incorrect instructions

CSCua21363

1550 byte block depletion related to TCP

CSCua27134

Traceback in Thread Name: Dispatch Unit

CSCua68934

ASA: May log 305006 regular translation creation failed messages.

CSCua69559

ASA-SM: inspect ipsec-pass-thru command is not available

CSCub16427

Standby ASA traceback while replicating flow from Active

CSCub37882

Standby ASA allows L2 broadcast packets with asr-group command

CSCub75595

ASA-SM does not allow slot number in prompt

 

 

Revision:  Version 8.5.1(7) – 02/29/2012

Files:  asa851-7-smp-k8.bin

Defects resolved since 8.5.1(6):

 

CSCtu34878

HA conn replications on smp platform needs to be throttled

 

Revision:  Version 8.5.1(6) – 01/27/2012

Files:  asa851-6-smp-k8.bin

Defects resolved since 8.5.1:

 

CSCsy68961

ASA 5580 reboots with traceback in threat detection

CSCtc79873

ASA 8.2 may calculate memory usage incorrectly

CSCte01475

EIGRP : static route redistribution with distribute-list not working

CSCte76002

Low performance over shared vlans in multi-mode

CSCtg76404

Traceback in Thread Name: Checkheaps due to logging

CSCth14248

ASA not sending all logging messages via TCP logging

CSCth37641

Write Mem on active ASA 8.3 produces log 742004 on standby

CSCth40316

Unable to edit the privilege level for cmd object & object-group in 8.3

CSCth58048

Assert Failure caused Traceback in Thread Name: Dispatch Unit

CSCth77370

IPv6 : ASA Stops responding to IPv6 ND sollicitation

CSCti10186

ASA 8.0.5.9 Standby with a traceback in Thread Name:Checkheaps

CSCti54387

ASA 8.2.2.x traceback in Thread Name: Dispatch Unit

CSCti54545

EIGRP metrics will not update properly on ASA

CSCti59746

OSPF default-info originate fails with route-map matching sub-net routes

CSCti62667

Connections stay open w/ 'sysopt connection timewait' & NetFlow

CSCtj20724

ASA hitless upgrade from 8.2 to 8.3: upgraded unit reload upon conf sync

CSCtk84288

Syslog %ASA-7-108006 generated erroneously

CSCtk98431

Slow xlate expiration rate

CSCtl06156

NAT Xlate idle timer doesn't reset with Conn.

CSCtl23397

ASA may log negative values for Per-client conn limit exceeded messg

CSCtl41335

ASA traceback when layer-2 adjacent TCP syslog server is unavailable

CSCtl58069

ASA - Traceback in thread DATAPATH-6-1330

CSCtl93641

ASA: Traceback in fover_parse thread after making NAT changes

CSCtn00318

ASA Unexpectedly Reloads with a Traceback due to a Watchdog Failure

CSCtn14091

ASA reuses tcp port too quickly

CSCtn38584

the packet is discarded when the specific xlate is exist.

CSCtn41850

"ERROR:doesn't match an existing object or object-group" with context

CSCtn60457

ASA 8.4.1 traceback on thread name ldap_client_thread with kerberos

CSCtn74485

ASA5580 traceback in DATAPATH-7-1353

CSCtn74649

BTF DNS-Snooping TTL maxes out at 24 hours, less than actual TTL

CSCtn75476

ASA Traceback in Thread Name: snmp

CSCtn77962

Tmatch: Traceback on Primary when adding User Group based ACL

CSCtn80920

LDAP Authorization doesn't block AccountExpired VPN RA user session

CSCtn90643

Traceback while replicating xlates on standby

CSCtn93345

ASA Broadview deny lines in NAT exemption ACL are migrated as permits

CSCto34823

multicast packets dropped in the first second after session creation

CSCto40365

Crafted TACACS+ reply considered as successful auth by ASA

CSCto48254

ASA reset TCP socket when RTP/RTCP arrives before SIP 200 OK using PAT

CSCto53199

Traceback with phone-proxy Thread Name: Dispatch Unit

CSCto62499

OSPF Failover causes 5 second convergence delay

CSCto81636

IPv6 traffic not updated after neighbor changes

CSCto82315

Traceback in Thread Name: gtp ha bulk sync with failover config

CSCto83156

ASA Sequence of ACL changes when changing host IP of object network

CSCto87589

Access-list remarks are lost during migration to 8.3

CSCtq07658

ASA: Traceback in ci/console on Standby unit

CSCtq10528

Host listed in object group TD shun exception gest shunned

CSCtq28561

asa 8.4, failover , ospf routing can not update rightly.

CSCtq35045

HA: Monitored interfaces fail to move out of waiting state

CSCtq44306

ASA-SM: Failover Cold Standby "Unable to sync configuration from Active"

CSCtq46808

ASA rebooted unit always become active on failover setup

CSCtq60450

Degraded Xlate Teardown Performance

CSCtq72776

ASA may reload in threadname Dispatch unit

CSCtq78280

invalid command dhcp client xxx on ASA 8.4

CSCtq79834

ASA traceback due to dcerpc inspection.

CSCtq84364

High CPU and Orphaned SSH session for on ASA 8.3(2.8)

CSCtq86859

Traceback in Thread Name: IP SLA Mon Event Processor

CSCtq90084

ASA traceback in thread Dispatch Unit

CSCtq94775

Unable to get block detail about 2048 byte blocks

CSCtq96616

ASA - LU allocate connection failed with conn-max policy

CSCtr03856

Failure to migrate named interfaces in ctx to 8.4 bridge group syntax

CSCtr15722

Memory fragmentation issue with dscp

CSCtr27161

EIGRP 'no default-information in' does not work

CSCtr31788

Standby ASA generates syslog 210005 while transmitting data on FTP

CSCtr39013

ASA - panic traceback when issuing show route interface_name

CSCtr44913

ASA 5580 traceback with DATAPATH-2-1024 thread

CSCtr47517

Protocol-Independent Multicast Denial of Service Vulnerability

CSCtr55374

ASA: asr-group in TFW A/A FO doesn't rewrite dst MAC for IP fragments

CSCtr62720

conns are not fully replicated to standby if config has many ACLs

CSCtr63728

ASA reloads with traceback in Thread Name : Dispatch Unit

CSCtr65241

connections are not replicated to standby unit

CSCtr74940

Active ASA traceback Thread: DATAPATH-3-1290, rip spin_lock_get_actual

CSCtr78703

ASA 8.4.2 http inspection might break certain flows intermittently

CSCtr91981

LDAP authentication fails when no RootDSE info returned

CSCtr94429

ASA: Local-host and all conns are torn down when client hits conn limit

CSCts00158

ASA EIGRP route not updated after failover

CSCts07069

ASA: Packet classifier fails with 'any' in Object NAT rule

CSCts09257

Traceback in sch_dispatcher thread

CSCts14130

100% CPU Object Group Search under low traffic due to spin_lock

CSCts15920

ASA: WCCP with authentication fails in 8.3 and 8.4

CSCts18026

ASA 5520 8.2.5 : traceback at thread name snmp

CSCts26909

CPU spikes to 100% and causes traceback when Syslog interface is down

CSCts41215

NAC Framework - Status Query triggers full Posture Revalidation

CSCts43136

ESMTP drops email with DKIM header

CSCts45638

8.4.2.2: Thread Name: DATAPATH-0-1272 Page fault: Unknown

CSCts46366

Slow memory leak by skinny

CSCts48937

Memory leak in DP udp host logging resulting in 1550 byte blocks leak

CSCts52885

Unexpected packet denials during large ACL compilation

CSCts65027

Mismatched Auto-Generated MACs on Etherchannel Interfaces in Failover

CSCts69531

Traceback in Dispatch Unit on Standby with timeout floating-conn

CSCts72339

L2 table entried for identity i/f not handle properly when add/del i/f

CSCts76258

xlate objects with no associated conns and idle timer >  timeout

CSCtt00286

ASA5585 Page fault traceback in Thread Name: DATAPATH-5-2312

CSCtt02413

DCERPC inspection does not properly fix up port and IP in Map Response

CSCtt02423

ASA: May traceback when adding ipv6 route before enabling ipv6

CSCtt03480

ASA Radius User-Password attribute is not included in Access-Request

CSCtt04665

Traceback in Thread Name: IP Address Assign

CSCtt11835

Traceback in Thread Name: tacplus_snd

CSCtt18185

ASA traceback cause by Global Policy

CSCtt19760

ASA may traceback in a DATAPATH thread

CSCtt25173

ASA 5520 8.2.5 memory leak in the inspect/gtp area

CSCtt27599

Standby Firewall traceback citing nat_remove_policy_from_np+383

CSCtt29810

AAA Command Authorization Reactivates Failed Server on Every Attempt

CSCtt32565

Specific closing sequence may cause ESMTP inspect to hog CPU for 1+ sec

CSCtt41809

ASASM traceback in DATAPATH-3-2265

CSCtt45496

ASA traceback in thread ci/console with names > 48 char in prefix-list

CSCtt76391

SNMPv3 Information Disclosure Vulnerability

CSCtt96550

ASA - Dispatch unit traceback - snp_nat_xlate_timeout

CSCtu19300

ASA may reload with traceback in Thread Name: kerberos_recv

CSCtu25253

show shared license' after toggle license-server causes traceback

CSCtu34217

High CPU usage during bulk sync on spin_lock used by tmatch lookup

CSCtu34220

High CPU usage during bulk sync when allocating NAT xlate

CSCtu40752

5580: assert failure in thread CP Processing

CSCtw35765

Threat Detection Denial Of Service Vulnerability