Resolved Issues

Bugs listed for a patch were verified as resolved when that patch was initially released.


Note

For your convenience, this document provides lists of resolved bugs for each patch. These lists are auto-generated once and are not subsequently updated. Depending on how and when a particular resolved issue was categorized or updated in our system, it may not appear in the release notes. You should regard the Cisco Bug Search Tool as the 'source of truth.'


Searching for Resolved Issues

If you have a support contract, you can use the Cisco Bug Search Tool to obtain an up-to-date list of resolved bugs for Firepower products. These general queries display resolved bugs for Firepower products running Version 6.5.0.x patches:

You can constrain searches to bugs affecting specific Firepower platforms and versions. You can also search by bug ID, or for specific keywords.

Version 6.5.0.4 Resolved Issues

Table 1. Version 6.5.0.4 Resolved Issues
Bug ID Headline

CSCvq35440

Upgrade Enhancements to STRAP verification for anyconnect - Cisco VPN session replay vulnerability

CSCvs55990

Deployment failure with SI DNS configured on FTD managed locally / FDM

CSCvs86257

FMC Upgrade is failing at 800_post/1025_vrf_policy_upgrade.pl

Version 6.5.0.3 Resolved Issues

Version 6.5.0.3 was removed from the Cisco Support & Download site on 2019-02-04 (for FMCs) and 2020-03-02 (for devices). If you are running this version, it is safe to continue. The bugs listed here are also fixed in Version 6.5.0.4.

Table 2. Version 6.5.0.3 Resolved Issues
Bug ID Headline

CSCvd33448

fireamp.pl using 100% Cpu after restore backup.

CSCvk55766

Try to assign devices to platform settings policy list of devices randomly disappear under policy

CSCvm85823

Not able to ssh, ssh_exec: open(pager) error on console

CSCvo76866

Traceback on 2100 - watchdog

CSCvp04134

Traceback in HTTP Cli Exec when upgrading to 9.12.1

CSCvp06526

Manage the sfhassd thread CPU affinity to match the Snort CPU affinity

CSCvp70833

ASA/FTD: Twice nat Rule with same service displaying error "ERROR: NAT unable to reserve ports"

CSCvq29167

Physical interface goes to link UP state in spite of disable interface during bootingup.

CSCvq46587

After failover, Active unit tcp sessions are not removed when timeout reached

CSCvq50587

ASA/FTD may traceback and reload in Thread Name 'BGP Router'

CSCvq51284

FPR 2100, low block 9472 causes packet loss through the device.

CSCvq76198

Traffic interruptions for FreeBSD systems

CSCvq81516

VPN events between 12 and 1 PM UTC are not displayed on the FMC

CSCvq87797

Multiple context 5585 ASA, transparent context losing mangement interface configuration.

CSCvq88644

Traceback in tcp-proxy

CSCvq93572

Unable to add user on FTD using external authentication

CSCvq96495

Console connection for FPR2100 is disconnected randomly about 20 minutes.

CSCvr13278

PPPoE session not coming up after reload.

CSCvr20486

FTD 1010 Passive interfaces does not receive unicast packets

CSCvr21803

Mac address flap on switch with wrong packet injected on ingress FTD interface

CSCvr25768

ASA may traceback on display_hole_og

CSCvr29978

Changing a rule and saving quickly might remove configuration.

CSCvr38379

Upgraded FTD will not reimage to base FTD version with the use of 'auto-install' feature in FPR2100

CSCvr50266

Dual stack ASAv failover triggered by reload issue

CSCvr53058

AC policy lookup done for SYN+ACK packet when tcp-intercept and a monitor AC policy is configured

CSCvr54054

Mac Rewrite Occurring for Identity Nat Traffic

CSCvr54980

FPR2100: Power doesn't turn off after turned off the power button on back of chassis

CSCvr55400

FTD/LINA traceback and reload observed in thread name: cli_xml_server

CSCvr55678

ClamAV zip-bomb Migration Vulnerability for 6.5.0.2 and above

CSCvr60111

configurations getting wiped off from standby, while deployment fails on active

CSCvr61492

device loading slow, related REST API calls

CSCvr66768

Lina Traceback during FTD deployment when PBR config is being pushed

CSCvr72665

FMC upgrading to 6.3/6.4 shouldn't remove existing deprecated flexconfig

CSCvr73115

Initial FTD Deploy After Policy Import causes Unused Objects which bloat policy size

CSCvr78166

Deployment failed on FTD with reason "failed to retrieve running configuration"

CSCvr78832

SSH: Newly created Local Users unable to login when device is managed locally

CSCvr81457

FTD traceback when TLS tracker (tls_trk_sniff_for_tls) attempted to free a block.

CSCvr82133

Unable to add routes and select interface from Device management page after FMC upgrade to 6.5

CSCvr84572

FMC 6.5 - Failed user login on FMC does not record entry in audit log

CSCvr85295

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote

CSCvr86213

CD is required to ignore Cluster-Msg-Delivery-Confirmation in Cluster Node Release Lina State

CSCvr90768

FTD: Deployment through slow links may fail

CSCvs10443

6.5 CloudEvent code writes config files in a way that 6.4 code does not understand

CSCvs10526

Throttle SSE Attempts on FTDs

CSCvs15276

ERROR: entry for ::/0 exists when configuring ipv6 icmp

CSCvs32023

Disable egress-optimization by default

CSCvs39589

ASA doesn't honor SSH Timeout When Data Channel is not Negotiated

CSCvs40531

AnyConnect 4.8 is not working on the FPR1000 series

CSCvs53705

Anyconnect sessions limited incorrectly

CSCvs61555

Policy Deployment Failures and Intrusion Policy Editor hanging due to improper Snort deletion

Version 6.5.0.2 Resolved Issues

Table 3. Version 6.5.0.2 Resolved Issues
Bug ID Headline

CSCvr52109

FTD may not match correct Access Control rule following a deploy to multiple devices

CSCvr88123

multi-deploy causes a sudden drop of intrusion events

CSCvs28768

Cisco Firepower Software WhatFix Walkthrough Data Issue

Version 6.5.0.1 Resolved Issues

Version 6.5.0.1 was removed from the Cisco Support & Download site on 2019-12-19. If you are running this version, we recommend you upgrade. The bugs listed here are also fixed in Version 6.5.0.2.

Table 4. Version 6.5.0.1 Resolved Issues
Bug ID Headline

CSCva36446

ASA Stops Accepting Anyconnect Sessions/Terminates Connections Right After Successful SSL handshake

CSCvo88762

FTD inline/transparent sends packets back through the ingress interface

CSCvp29554

Watchdog traceback due to lina_host_file_stat calls

CSCvp69229

OpenSSL 0-byte Record Padding Oracle Information Disclosure Vulnerabil

CSCvp81083

ASA/Lina Traceback related to TLS/VPN

CSCvq09093

VPN Pre-deploy validations takes around 20 seconds for each device

CSCvq29969

Firepower Recommendations rule count changes even when not regenerated

CSCvq40943

FTD 4150 VPN s2s deployment failure with 6K spokes

CSCvq43453

Overrides cannot be added for port object if it is used in variable sets in sub domains

CSCvq45000

Policy deployment to FP 8000 sensor is failing when NAT is configured

CSCvq53915

Cisco Firepower Management Center Multiple Cross-Site Scripting Vulnerabilities

CSCvq56257

Cached malware disposition does not always expire as expected

CSCvq63024

Dual stacked ASAv manual failover issues

CSCvq67271

Retrieving an specfic rule by ID of a child Access Policy returns a 404 : Not Found status.

CSCvq70485

Slow "securityzones" REST API

CSCvq70775

FPR2100 FTD Standby unit leaking 9K blocks

CSCvq83019

Long processing time to insert policy deploy task if many application filter object used in ACPolicy

CSCvq83168

DNS lookup using mgmt VRF not possible because FMC doesn't allow interface after server address

CSCvq92126

ASA traceback in Thread IPsec Message Handler

CSCvq93640

WRL6 and WRL8 commit id update in CCM layer (sprint 67)

CSCvq94729

Deployment rollback causes momentary traffic drop when error in a LINA ONLY section of delta cli

CSCvq95058

IPSEC SA is deleted by failover which is caused by link down

CSCvr00892

where clause not working for external data base access

CSCvr04954

FMC 6.4.0 - Stack unit on different Domain fails the deployment after upgrade

CSCvr07421

Policy deployment fails with 400+ interfaces in security zone due to incorrect formation of deployDB

CSCvr10777

ASA Traceback in Ikev2 Daemon

CSCvr11395

Only a subset of devices where deployed from a device group during scheduled deploy

CSCvr12018

ASA: VPN traffic fails to take the tunnel route when the default route is learnt over BGP.

CSCvr23580

Can't delete 2 or more than two IP address-pool

CSCvr25954

FTD/LINA Standby may traceback and reload during logging command replication from Active

CSCvr27445

App-sync failure if unit tries to join HA during policy deployment

CSCvr29638

HA FTD on FPR2110 crash after deploy ACP from FMC

CSCvr35956

Block double-free when combining ServerKeyExchange and ClientKeyExchange fails --> lina crashes

CSCvr36687

Overrides cannot be added for network object if it is used in variable sets in sub domains

CSCvr37486

established rules in asp table are not un-installed on config removal

CSCvr44123

Unable to login via chassis Manager or Rest api in FPR2100 if session timeout is non-deafult

CSCvr95287

Cisco Firepower Management Center LDAP Authentication Bypass Vulnerability