Resolved Issues

For your convenience, the release notes list the resolved issues for each patch.

If you have a support contract, you can use the Cisco Bug Search Tool to obtain up-to-date bug lists. You can constrain searches to bugs affecting specific platforms and versions. You can also search by bug status, bug ID, and for specific keywords.


Important

Bug lists are auto-generated once and are not subsequently updated. Depending on how and when a bug was categorized or updated in our system, it may not appear in the release notes. You should regard the Cisco Bug Search Tool as the source of truth.


Version 6.5.0.5 Resolved Issues

Table 1. Version 6.5.0.5 Resolved Issues

Bug ID

Headline

CSCtb41710

ASA revocation-check to fall back to none only if CDP is unavailable

CSCuj60109

ENH: SFP transceivers attached to ASA-IC-6GE-SFP-A are not shown by CLI

CSCuw95798

Cisco Firepower Management Center Software Cross-Site Scripting Vulnerabilities

CSCuy53106

ASA OS incorrectly calculates certificate expiry date in Syslog 717054

CSCuz24872

Original Client IP does not populate for dropped events when inline normalization enabled

CSCvb92169

ASA should provide better fragment-related logs and ASP drop reasons

CSCvg59385

ASA scansafe connector takes too long to failover to secondary CWS Tower

CSCvj00997

"show open-network-ports" not showing the proper information on FPR4100 Series

CSCvj93609

ASA traceback on spin_lock_release_actual

CSCvm77115

Lina Traceback due to invalid TSC values

CSCvn27043

Hostscan: LastSuccessfulInstallParams can not be detected by Hostscan

CSCvn64647

ASA traceback and reload due to tcp_retrans_timeout internal thread handling

CSCvn93683

ASA: cluster exec show commands not show all output

CSCvo60166

KP: Can't login to fxos due to disk full error

CSCvp57643

FTD/ASA - Cluster/HA - Master/Active unit does not update all the route changes to Slaves/Standby

CSCvp60088

2100 generating error on FMC "[FSM.FAILED].Retrieve application attributes"

CSCvp67033

ASA: Cannot distinguish name aliases for IPv6 and displays a "incomplete command" error message

CSCvp93468

Cisco ASA Software and Cisco FTD Software SSL VPN Denial of Service Vulnerability

CSCvp94478

ASA scp quite slow

CSCvp99327

FMC UI Unresponsive After Attempt To Register Smart License With Smart Satellite

CSCvq20707

Snort rendering block verdict for rules with action of alert.

CSCvq24258

Increase number of worker for mojo-server on large appliances

CSCvq34340

FTD traffic outage due to 9344 block size depletion caused by the egress-optimization feature

CSCvq37913

VPN-sessiondb does not replicate to standby ASA

CSCvq38889

slib memory manager : mempool mutex vs spinlock selection

CSCvq39344

Firepower managed devices may stop responding to SNMPv3 GET/WALK requests

CSCvq43920

Cisco Firepower Threat Defense Software Hidden Commands Vulnerability

CSCvq50944

OSPFv3 neighborship is flapping every ~30 minutes

CSCvq53902

Cisco Firepower Management Center Multiple Cross-Site Scripting Vulnerabilities

CSCvq55426

Adding an ipv6 default route causes CLI to hang for 50 seconds

CSCvq61601

OpenSSL vulnerability CVE-2019-1559 on FTD

CSCvq65864

Traceback in HTTP Cli Exec with rest-api agent enabled

CSCvq73464

ipv6 address of asa where ip-client is enabled is not showing in snmptrap logs

CSCvq78126

V route is missing even after setting the reverse route in Crypto map config in HA-IKEv2

CSCvq84430

ASA appliance mode shows port-channel member interfaces as "unassociated"

CSCvq93640

WRL6 and WRL8 commit id update in CCM layer (sprint 67)

CSCvq95826

DCD Causes Standby to send probes

CSCvq99107

Hot swap of SFP is not taking effect on the ASA

CSCvr02080

CPU Hogs observed in CERT API process while decoding the CRL with large number of entries in it

CSCvr07460

ASA traceback and reload related to crypto PKI operation

CSCvr09399

Dynamic flow-offload can't be disabled

CSCvr09468

ASA traceback and reload for the CLI "Show nat pool"

CSCvr15503

ASA: SSH and ASDM sessions stuck in CLOSE_WAIT causing lack of MGMT for the ASA

CSCvr17735

SFDataCorrelator high CPU during SI update

CSCvr19922

Cluster: BGP route may go in out of sync in some scenarios

CSCvr20449

Policy deployment is reported as successful on the FMC but it is actually failed

CSCvr20486

FTD 1010 Passive interfaces does not receive unicast packets

CSCvr20757

Block leak on ASA while running Cisco Umbrella DNS inspection

CSCvr20876

low memory causes kernel to invoke - oom and reload device - modified rlimit for KP

CSCvr20893

FTD in HA pair crashes in ids_event_proce process after policy deployment

CSCvr23986

Cisco ASA & FTD devices may reload under conditions of low memory and frequent complete MIB walks

CSCvr30694

FMC : FMC detect HA Sync Failed

CSCvr33586

FPR1010 - Add temperature/warnings for SSD when thresholds are exceeded

CSCvr35125

Packet loss over failover link triggers Split-Brain

CSCvr37502

libexpat Improper Parsing Denial of Service Vulnerability

CSCvr39556

Segfault in libclamav.so (in the context of SFDataCorrelator)

CSCvr42344

Traceback on snp_policy_based_route_lookup when deleting a rule from access-list configured for PBR

CSCvr43341

FDM 6.5.0 - FPR1000 GUI Unresponsive if upgraded with Trunk Interfaces

CSCvr49729

Fail-to-Wire ports showing down for FPR2100, FTW configuration API takes long to finish

CSCvr49833

Cisco Firepower 2100 Series Security Appliances ARP Denial of Service Vulnerability

CSCvr50509

Some 3DES related configurations are lost after booted

CSCvr50630

ASA Traceback: SCTP bulk sync and HA synchronization

CSCvr51955

Estreamer should terminate a connection when not receiving ACKs for a long time

CSCvr51998

ASA Static route disappearing from asp table after learning default route via BGP

CSCvr55518

Missing clean up on rule creation failure.

CSCvr56031

FTD/LINA Traceback and reload observed in thread name: cli_xml_server

CSCvr57605

ASA after reload had license context count greater than platform limits

CSCvr58411

RRI on static HUB/SPOKE config is not working on HUB when a new static SPOKE is added or deleted

CSCvr61252

systems must enforce controls that prevent confidential information from being stored within cookie

CSCvr66840

Management Interface operational state related fault is seen on fpr1000/fpr2100 platforms

CSCvr68146

Unable to auto-rejoin FTD cluster

CSCvr70895

LCMB: Dynamic medium page allocation can lead to memory depletion

CSCvr76029

FTD-HA: after restoring FTD-HA backup file, snort process will be down

CSCvr79974

Configuration might not replicated if packet loss on the failover Link

CSCvr80164

WR6 and WR8 commit id update in CCM layer(sprint 72)

CSCvr80621

FMC External Authentication with SecurID RSA fails with banner enabled

CSCvr86077

ASA Traceback/pagefault in Datapath due to re_multi_match_ascii

CSCvr89663

Traceback: with thread name: pix_flash_config_thread WM1010 went into reboot loop

CSCvr90965

FTDv Deployment in Azure causes unrecoverable traceback state due to no dns domain-lookup any"

CSCvr92168

Cisco ASA and Cisco FTD Software OSPF Packets Processing Memory Leak Vulnerability

CSCvr92311

Standby ASA logging %ASA-4-720022: (VPN-Secondary) Cannot find trust point __tmpCiscoM1Root__

CSCvr92327

ASA/FTD may traceback and reload in Thread Name 'PTHREAD-1533'

CSCvr92617

NPE in SecurityIntelligenceEoConvertor causes Lucene indexing failure

CSCvr93978

ASA traceback and reload on Thread DATAPATH-0-2064

CSCvr99222

NTP configuration is not synchronized to LINA on Multi Instance

CSCvs00023

port manager crashes with "shutdown" command from clish CLI

CSCvs01422

Lina traceback when changing device mode of FTD

CSCvs02954

ASA OSPF: Prefix removed from the RIB when topology changes, then added back when another SPF is run

CSCvs03023

Clustering module needs to skip the hardware clock update to avoid the timeout error and clock jump

CSCvs04067

Not able to access FMC devices with Chrome on Mac after upgrade to Catalina.

CSCvs04179

ASA - 9.8.4.12 traceback and reload in ssh or fover_rx Thread

CSCvs05066

Snort file mempool corruption leads to performance degradation and process failure.

CSCvs05262

Decrement TTL display wrong result

CSCvs07668

FTD traceback and reload on thread DATAPATH-1-15076 when SIP inspection is enabled

CSCvs07982

ASA TRACEBACK: sctpProcessNextSegment - SCTP_INIIT_CHUNK

CSCvs09533

FP2100: Traceback and reload when processing traffic through more than two inline sets

CSCvs10748

Cisco ASA Software and FTD Software Web Services Denial of Service Vulnerability

CSCvs15972

Network Performance Degradation when SSL policy is enabled

CSCvs16073

snmp poll failure with host and host-group configured

CSCvs16395

Unable to download bundles on FPR2100

CSCvs17319

[IMS_6_7_0] WM 'format everything' command bricks the device starting with fxos 82.9.1.112

CSCvs19968

Fix consoled from getting stuck and causing HA FTD policy deployment errors.

CSCvs23040

Expected output for time zone is not found while executing "show clock" command.

CSCvs24215

Firepower Device Manager (FDM) option to disable SSL rekey is not reflected on the config

CSCvs26402

NAT policy configuration range limit to be imposed for non service cmds as well

CSCvs27264

mroute entries on ASA not getting refreshed.

CSCvs28213

ASA Traceback in Thread Name SSH with assertion slib_malloc.c

CSCvs28290

Cisco Firepower Threat Defense Software SSL Input Validation Denial of Service Vulnerabili

CSCvs28580

Traceback when processing SSL traffic under heavy load

CSCvs29779

ASA may traceback and reload while waitinPC g for "DATAPATH-12-1899" process to finish.

CSCvs31159

Incorrect empty location handling inside CSCOGet_location wrapper

CSCvs31443

ASA reporting negative memory values on "%ASA-5-321001: Resource 'memory' limit'" message

CSCvs31470

OSPF Hello causing 9K block depletion, control point CPU 100% and cluster unstable.

CSCvs32907

Addition of debug counters for STRAP implementation.

CSCvs33102

ASA/FTD may traceback and reload in Thread Name 'EIGRP-IPv4'

CSCvs33416

Upgrade kernel to cpe:2.3:o:linux:linux_kernel:4.14.158:

CSCvs33852

After upgrade to version 9.6.4.34 is not possible to add an access-group

CSCvs34854

FMC generates referred interfaces cli delta after access-list cli delta

CSCvs37013

Prevent octeon_init from getting stuck and causing HA FTD policy deployment errors.

CSCvs38785

Inconsistent timestamp format in syslog

CSCvs40230

ICMP not working and failed with inspect-icmp-seq-num-not-matched

CSCvs42799

After FXOS upgrade, App Instance failed to start with Checksum Verification Fail

CSCvs43154

Secondary ASA is unable to join the failover due to aggressive warning messages.

CSCvs45111

WR6 and WR8 commit id update in CCM layer(sprint 75)

CSCvs45548

reactivation-mode timed causing untimely reactivation of failed server

CSCvs47252

ASA traceback and reload when running command "clear capture /"

CSCvs47283

Traffic may match an access-list incorrectly with object-group-search enabled

CSCvs50459

Cisco ASA and Cisco FTD Malformed OSPF Packets Processing Denial of Service Vulnerability

CSCvs50931

Policy deployment fails subsequent to SRU

CSCvs50952

Upgrade of 6.4.0.4-34 to 6.4.0.6 is deleting Static Route

CSCvs52169

ASA sends malformed RADIUS message when device-id from AnyConnect is too long

CSCvs55603

ICMP Reply Dropped when matched by ACL

CSCvs56888

Cisco Firepower Threat Defense Software TCP Flood Denial of Service Vulnerability

CSCvs59056

ASA/FTD Tunneled Static Routes are Ignored by Suboptimal Lookup if Float-Conn is Enabled

CSCvs59487

Observed crash in KP device while upgrading to 99.14.1.64 image.

CSCvs59866

Remove unsupported fast mode lacppolicy configuration from FXOS on Firepower 2100

CSCvs59966

false reported value for OID "cipSecGlobalActiveTunnels" - same as ASDM

CSCvs61392

On firepower devices, hardware rules are not updated after successful policy deployment

CSCvs61701

DME process crash due to memory leak on Firepower 2100

CSCvs63484

SAML tokens are not removed from hash table

CSCvs70260

IKEv2 vpn-filter drops traffic with implicit deny after volume based rekey collision

CSCvs71766

Cisco Firepower Management Center Software Open Redirect Vulnerability

CSCvs72393

FPR1010 temperature thresholds should be changed

CSCvs73663

ASA Traceback on IPsec message handler Thread

CSCvs73754

ASA/FTD: Block 256 size depletion caused by ARP of BVI not assigned to any physical interface

CSCvs74452

SFDatacorrelator and Snort process cores repeatedly while loading malware seed file

CSCvs76605

Wrong Module version listed for FXOS 2.6(1.174)

CSCvs77334

FTD failover due to error "Inspection engine in other unit has failed due to snort and disk failure"

CSCvs77818

Traceback: spin_lock_fair_mode_enqueue: Lock (np_conn_shrlock_t) is held for a long time

CSCvs78252

ASA/Lina Offloaded TCP flows interrupted if TCP sequence number randomizer is enabled and SACK used

CSCvs79023

ASA/FTD Traceback in Thread Name: DATAPATH due to DNS inspection

CSCvs80157

ASA Traceback Thread Name: IKE Daemon

CSCvs80536

FP41xx incorrect interface applied in ASA capture

CSCvs82726

Placeholder to address CSCvs31470 in Multi-Context Mode

CSCvs85467

Multiple Cisco Products Snort Application Detection Engine Policy Bypass Vulnerability

CSCvs87168

SNORT Fatal Error due to out of range interface ID

CSCvs88413

Port-channel bundling is failing after upgrade to 9.8 version

CSCvs90100

ASA/FTD may traceback and reload in Thread Name 'License Thread'

CSCvs91389

FTD Traceback Lina process

CSCvs91869

FPR-1000 Series Random Number Generation Error

CSCvs94061

NTP script error leading to clock drift and traffic interruption

CSCvs94486

CSCvs59487 requires additional fix for resolution

CSCvs97863

Reduce number of fsync calls during close in flash file system

CSCvs97908

Invalid scp session terminates other active http, scp sessions

CSCvs98634

catalina.<date>.log files can consume all disk space in their partition

CSCvt00113

ASA/FTD traceback and reload due to memory leak in SNMP community string

CSCvt01282

WR6 and WR8 commit id update in CCM layer(sprint 79)

CSCvt01397

Deployment is marked as success although LINA config was not pushed

CSCvt02409

Cisco Firepower Threat Defense Software Inline Pair/Passive Mode DoS Vulnerability

CSCvt03598

Cisco ASA Software and FTD Software Web Services Read-Only Path Traversal Vulnerability

CSCvt04377

When maximum packet encapsulation is exceeded decoding errors are depleting disk space.

CSCvt05862

IPv6 DNS server resolution fails when the server is reachable over the management interface.

CSCvt06606

Flow offload not working with combination of FTD 6.2(3.10) and FXOS 2.6(1.169)

CSCvt06841

Incorrect access-list hitcount seen when configuring it with a capture on ASA

CSCvt09940

Cisco Firepower 4110 ICMP Flood Denial of Service Vulnerability

CSCvt11661

DOC - Clarify the meaning of mp-svc-flow-control under show asp drop

CSCvt11742

ASA/FTD may traceback and reload in Thread Name 'ssh'

CSCvt12463

ASA: Traceback in thread Unicorn Admin Handler

CSCvt13445

Cisco ASA and FTD Software FTP Inspection Bypass Vulnerability

CSCvt15062

FTD 2100: Packet drops during the transition of BYPASS to NON-BYPASS when device is rebooted

CSCvt15163

Cisco ASA and FTD Software Web Services Information Disclosure Vulnerability

CSCvt18028

Cisco ASA and FTD WebVPN CRLF Injection Vulnerability

CSCvt21041

FTD Traceback in thread 'ctm_ipsec_display_msg'

CSCvt23643

VPN failover recovery is taking approx. 30 seconds for data to resume

CSCvt24328

FTD: Traceback and reload related to lina_host_file_open_raw function

CSCvt25225

ASA: Active unit HA traceback and reload during Config Sync state during OSPF sync

CSCvt26031

ASAv Unable to register smart licensing with IPv6

CSCvt26067

Active FTP fails when secondary interface is used on FTD

CSCvt26520

with FXOS 2.8.1.84, FDM UI installation of 6.5.0.2 patch fails. unzip -o fails to unzip all files

CSCvt27585

Observed traceback on 2100 while performing Failover Switch from Standby.

CSCvt28182

sctp-state-bypass is not getting invoked for inline FTD

CSCvt29049

FPR2100 - ASA in Appliance Mode - SNMP Delay

CSCvt30731

WR6, WR8 and LTS18 commit id update in CCM layer(sprint 80)

CSCvt31177

Cisco ASA and FTD Software for FP 1000/2100 Series Appliances Secure Boot Bypass Vulns

CSCvt31178

Cisco ASA and FTD Software for FP 1000/2100 Series Appliances Secure Boot Bypass Vulns

CSCvt33785

IPSec SAs are not being created for random VPN peers

CSCvt35897

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DoS Vuln

CSCvt35945

Encryption-3DES-AES should not be required when enabling ssh version 2 on 9.8 train

CSCvt36542

Multi-context ASA/LINA on FPR not sending DHCP release message

CSCvt41333

Dynamic RRI route is not destroyed when IKEv2 tunnel goes down

CSCvt43967

Pad packets received from RA tunnel which are less than or equal 46 bytes in length with zeros

CSCvt45863

Crypto ring stalls when the length in the ip header doesn't match the packet length

CSCvt46289

ASA LDAPS connection fails on Firepower 1000 Series

CSCvt46830

FPR2100 'show crypto accelerator statistics' counters do not track symmetric crypto

CSCvt48260

Standby unit traceback at fover_parse and boot loop when detecting Active unit

CSCvt48941

FTD Standby unit does not join HA due to "HA state progression failed due to APP SYNC timeout"

CSCvt50263

FMC Unable to fetch VPN troubleshooting logs from WM Model devices

CSCvt50946

Stuck uauth entry rejects AnyConnect user connections despite fix of CSCvi42008

CSCvt51346

PKI-CRL: Memory Leak on Download and Clear Large CRL

CSCvt51348

PKI-CRL: Memory Leak on Download Large CRL in loop without clearing it

CSCvt51349

Fragmented packets forwarded to fragment owner are not visible on data interface captures

CSCvt51987

Traffic outage due to 80 size block exhaustion on the ASA FPR9300 SM56

CSCvt52782

ASA traceback Thread name - webvpn_task

CSCvt54182

LINA cores are generated when FTD is configured to do SSL decryption.

CSCvt59015

KP IOQ driver. Add defensive parameter and state checks.

CSCvt59253

ASA 9.13.1.7 traceback and reload while processing hostscan data (process name LINA )

CSCvt60190

Cisco ASA and FTD Web Services File Upload Denial of Service Vulnerability

CSCvt63484

ASA High CPU with igb_saleen_io_sfp_mod_poll_thre process

CSCvt64035

remote acess mib - SNMP 64 bit only reporting 4Gb before wrapping around

CSCvt64270

ASA is sending failover interface check control packets with a wrong destination mac address

CSCvt64822

Cisco Adaptive Security Appliance Software SSL/TLS Denial of Service Vulnerability

CSCvt65982

Route Fallback doesn't happen on Slave unit, upon RRI route removal.

CSCvt66351

NetFlow reporting impossibly large flow bytes

CSCvt68131

FTD traceback and reload on thread "IKEv2 Mgd Timer Thread"

CSCvt68294

Adjust Firepower 4120 Maximum VPN Session Limit to 20,000

CSCvt70322

Cisco ASA Software and FTD Software Web Services Denial of Service Vulnerability

CSCvt73806

FTD traceback and reload on FP2120 LINA Active Box. VPN

CSCvt74037

Cisco FXOS Software Command Injection Vulnerability

CSCvt75241

Redistribution of VPN advertised static routes fail after reloading the FTD on FPR2100

CSCvt77813

High unmanaged disk usage on /ngfw due to cisco_uridb* files

CSCvt79709

FDM: Deployment Failure after editing NAT Policy containing Mapped Services

CSCvt79988

Policy deployment failure due to snmp configuration after upgrading FMC to 6.6

CSCvt83121

Cisco ASA and FTD Software OSPFv2 Link-Local Signaling Denial of Service Vulnerability

CSCvt83133

Unable to access anyconnect webvpn portal from google chrome using group-url

CSCvt86188

SNMP traps can't be generated via diagnostic interface

CSCvt90330

ASA traceback and reload with thread name coa_task

CSCvt91258

FDM: None of the NTP Servers can be reached - Using Data interfaces as Management Gateway

CSCvt92647

Connectivity over the state link configured with IPv6 addresses is lost after upgrading the ASA

CSCvt95517

Certificate mapping for AnyConnect on FTD stops working.

CSCvt97917

ASAv on AWS 9.13.1.7 BYOL image cannot be enabled for PLR

CSCvt98599

IKEv2 Call Admission Statistics "Active SAs" counter out of sync with the real number of sessions

CSCvu00112

tsd0 not reset when ssh quota limit is hit in ci_cons_shell

CSCvu03107

AnyConnect statistics is doubled in both %ASA-4-113019 and RADIUS accounting

CSCvu03562

Device loses ssh connectivity when username and password is entered

CSCvu03675

FPR2100: ASA console may hang & become unresponsive in low memory conditions

CSCvu04279

ASAv/AWS: Unable to upgrade or downgrade C5 ASAv code on AWS

CSCvu05216

cert map to specify CRL CDP Override does not allow backup entries

CSCvu05418

Import fails with local user password contains consecutive characters message

CSCvu07602

FPR-41x5: 'clear crypto accelerator load-balance' will cause a traceback and reload

CSCvu07880

ASA on QP platforms display wrong coredump filesystem space (50 GB)

CSCvu08013

DTLS v1.2 and AES-GCM cipher when used drops a particular size packet frequently.

CSCvu08422

Cisco Firepower Threat Defense Software Multi-Instance Container Escape Vulnerability

CSCvu12039

Cluster data unit might fail to synchronize SCTP configuration from the control unit after bootup

CSCvu12248

ASA-FPWR 1010 traceback and reload when users connect using AnyConnect VPN

CSCvu12684

HKT - Failover time increases with upgrade to 9.8.4.15

CSCvu15801

Cisco ASA and FTD Software SIP Denial of Service Vulnerability

CSCvu17924

FTD failover units traceback and reload on DATAPATH

CSCvu17965

ASA generated a traceback and reloaded when changing the port value of a manual nat rule

CSCvu20007

Config_XML_Response from LINA is not in the correct format,Lina reporting as No memory available.

CSCvu26296

ASA interface ACL dropping snmp control-plane traffic from ASA

CSCvu26561

WebVPN SSO Gives Unexpected Results when Integrated with Kerberos

CSCvu27868

ASA: Lack of specific syslog messages to external IPv6 logging server after ASA upgrade

CSCvu34413

SSH keys lost in ASA after reload

CSCvu40531

FXOS LACP packet logging to pktmgr.out and lacp.out fills up /opt/cisco/platform/logs to 100%

CSCvu43827

ASA & FTD Cluster unit traceback in thread Name "cluster config sync" or "fover_FSM_thread"

CSCvu44910

Cisco ASA Software and FTD Software Web Services Cross-Site Scripting Vulnerability

CSCvu46685

Cisco ASA and FTD Software SSL/TLS Session Denial of Service Vulnerability

CSCvu47925

Cisco ASA and FTD IP Fragment Memory Leak Vulnerability

CSCvu56286

FDM - New firewall session getting created after performing HA Failover for traffic in progress

CSCvu59817

Cisco ASA and FTD Software SSL VPN Direct Memory Access Denial of Service Vulnerability

CSCvu61919

WR6, WR8 and LTS18 commit id update in CCM layer(sprint 87)

CSCvu70529

Binary rules (SO rules) are not loaded when snort reloads

CSCvu75581

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvu75615

Cisco ASA Software and FTD Software WebVPN Portal Access Rule Bypass Vulnerability

CSCvu82743

Snort Generator ID 3 rules disabled following Snort reload

CSCvu83309

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvu85346

Restore backup fails on FTD models 2100 or 1100 platforms

CSCvv02245

ASA 'session sfr' command disconnects from FirePOWER module for initial setup

CSCvv02925

OSPF neighbourship is not establising

CSCvv13835

Cisco ASA and FTD Web Services Interface Cross-Site Scripting Vulnerabilities

CSCvv13993

Cisco Firepower 1000 Series Bleichenbacher Attack Vulnerability

CSCvv20450

FMC 6.4 to 6.7 upgrade fails "Error running script 500_rpms/110_generate_dbaccess.sh"

CSCvv33712

Cisco ASA Software Web-Based Management Interface Reflected Cross-Site Scripting Vulnerabi

CSCvv52591

DMA memory leak in ctm_hw_malloc_from_pool causing management and VPN connections to fail

CSCvw07000

Snort busy drops with PDTS Tx queue stuck

Version 6.5.0.4 Resolved Issues

Table 2. Version 6.5.0.4 Resolved Issues
Bug ID Headline

CSCvq35440

Upgrade Enhancements to STRAP verification for anyconnect - Cisco VPN session replay vulnerability

CSCvs55990

Deployment failure with SI DNS configured on FTD managed locally / FDM

CSCvs86257

FMC Upgrade is failing at 800_post/1025_vrf_policy_upgrade.pl

Version 6.5.0.3 Resolved Issues

Version 6.5.0.3 was removed from the Cisco Support & Download site on 2019-02-04 (for FMCs) and 2020-03-02 (for devices). If you are running this version, it is safe to continue. The bugs listed here are also fixed in Version 6.5.0.4.

Table 3. Version 6.5.0.3 Resolved Issues
Bug ID Headline

CSCvd33448

fireamp.pl using 100% Cpu after restore backup.

CSCvk55766

Try to assign devices to platform settings policy list of devices randomly disappear under policy

CSCvm85823

Not able to ssh, ssh_exec: open(pager) error on console

CSCvo76866

Traceback on 2100 - watchdog

CSCvp04134

Traceback in HTTP Cli Exec when upgrading to 9.12.1

CSCvp06526

Manage the sfhassd thread CPU affinity to match the Snort CPU affinity

CSCvp70833

ASA/FTD: Twice nat Rule with same service displaying error "ERROR: NAT unable to reserve ports"

CSCvq29167

Physical interface goes to link UP state in spite of disable interface during bootingup.

CSCvq46587

After failover, Active unit tcp sessions are not removed when timeout reached

CSCvq50587

ASA/FTD may traceback and reload in Thread Name 'BGP Router'

CSCvq51284

FPR 2100, low block 9472 causes packet loss through the device.

CSCvq76198

Traffic interruptions for FreeBSD systems

CSCvq81516

VPN events between 12 and 1 PM UTC are not displayed on the FMC

CSCvq87797

Multiple context 5585 ASA, transparent context losing mangement interface configuration.

CSCvq88644

Traceback in tcp-proxy

CSCvq93572

Unable to add user on FTD using external authentication

CSCvq96495

Console connection for FPR2100 is disconnected randomly about 20 minutes.

CSCvr13278

PPPoE session not coming up after reload.

CSCvr20486

FTD 1010 Passive interfaces does not receive unicast packets

CSCvr21803

Mac address flap on switch with wrong packet injected on ingress FTD interface

CSCvr25768

ASA may traceback on display_hole_og

CSCvr29978

Changing a rule and saving quickly might remove configuration.

CSCvr38379

Upgraded FTD will not reimage to base FTD version with the use of 'auto-install' feature in FPR2100

CSCvr50266

Dual stack ASAv failover triggered by reload issue

CSCvr53058

AC policy lookup done for SYN+ACK packet when tcp-intercept and a monitor AC policy is configured

CSCvr54054

Mac Rewrite Occurring for Identity Nat Traffic

CSCvr54980

FPR2100: Power doesn't turn off after turned off the power button on back of chassis

CSCvr55400

FTD/LINA traceback and reload observed in thread name: cli_xml_server

CSCvr55678

ClamAV zip-bomb Migration Vulnerability for 6.5.0.2 and above

CSCvr60111

configurations getting wiped off from standby, while deployment fails on active

CSCvr61492

device loading slow, related REST API calls

CSCvr66768

Lina Traceback during FTD deployment when PBR config is being pushed

CSCvr72665

FMC upgrading to 6.3/6.4 shouldn't remove existing deprecated flexconfig

CSCvr73115

Initial FTD Deploy After Policy Import causes Unused Objects which bloat policy size

CSCvr78166

Deployment failed on FTD with reason "failed to retrieve running configuration"

CSCvr78832

SSH: Newly created Local Users unable to login when device is managed locally

CSCvr81457

FTD traceback when TLS tracker (tls_trk_sniff_for_tls) attempted to free a block.

CSCvr82133

Unable to add routes and select interface from Device management page after FMC upgrade to 6.5

CSCvr84572

FMC 6.5 - Failed user login on FMC does not record entry in audit log

CSCvr85295

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote

CSCvr86213

CD is required to ignore Cluster-Msg-Delivery-Confirmation in Cluster Node Release Lina State

CSCvr90768

FTD: Deployment through slow links may fail

CSCvs10443

6.5 CloudEvent code writes config files in a way that 6.4 code does not understand

CSCvs10526

Throttle SSE Attempts on FTDs

CSCvs15276

ERROR: entry for ::/0 exists when configuring ipv6 icmp

CSCvs32023

Disable egress-optimization by default

CSCvs39589

ASA doesn't honor SSH Timeout When Data Channel is not Negotiated

CSCvs40531

AnyConnect 4.8 is not working on the FPR1000 series

CSCvs53705

Anyconnect sessions limited incorrectly

CSCvs61555

Policy Deployment Failures and Intrusion Policy Editor hanging due to improper Snort deletion

Version 6.5.0.2 Resolved Issues

Table 4. Version 6.5.0.2 Resolved Issues
Bug ID Headline

CSCvr52109

FTD may not match correct Access Control rule following a deploy to multiple devices

CSCvr88123

multi-deploy causes a sudden drop of intrusion events

CSCvs28768

Cisco Firepower Software WhatFix Walkthrough Data Issue

Version 6.5.0.1 Resolved Issues

Version 6.5.0.1 was removed from the Cisco Support & Download site on 2019-12-19. If you are running this version, we recommend you upgrade. The bugs listed here are also fixed in Version 6.5.0.2.

Table 5. Version 6.5.0.1 Resolved Issues
Bug ID Headline

CSCva36446

ASA Stops Accepting Anyconnect Sessions/Terminates Connections Right After Successful SSL handshake

CSCvo88762

FTD inline/transparent sends packets back through the ingress interface

CSCvp29554

Watchdog traceback due to lina_host_file_stat calls

CSCvp69229

OpenSSL 0-byte Record Padding Oracle Information Disclosure Vulnerabil

CSCvp81083

ASA/Lina Traceback related to TLS/VPN

CSCvq09093

VPN Pre-deploy validations takes around 20 seconds for each device

CSCvq29969

Firepower Recommendations rule count changes even when not regenerated

CSCvq40943

FTD 4150 VPN s2s deployment failure with 6K spokes

CSCvq43453

Overrides cannot be added for port object if it is used in variable sets in sub domains

CSCvq45000

Policy deployment to FP 8000 sensor is failing when NAT is configured

CSCvq53915

Cisco Firepower Management Center Multiple Cross-Site Scripting Vulnerabilities

CSCvq56257

Cached malware disposition does not always expire as expected

CSCvq63024

Dual stacked ASAv manual failover issues

CSCvq67271

Retrieving an specfic rule by ID of a child Access Policy returns a 404 : Not Found status.

CSCvq70485

Slow "securityzones" REST API

CSCvq70775

FPR2100 FTD Standby unit leaking 9K blocks

CSCvq83019

Long processing time to insert policy deploy task if many application filter object used in ACPolicy

CSCvq83168

DNS lookup using mgmt VRF not possible because FMC doesn't allow interface after server address

CSCvq92126

ASA traceback in Thread IPsec Message Handler

CSCvq93640

WRL6 and WRL8 commit id update in CCM layer (sprint 67)

CSCvq94729

Deployment rollback causes momentary traffic drop when error in a LINA ONLY section of delta cli

CSCvq95058

IPSEC SA is deleted by failover which is caused by link down

CSCvr00892

where clause not working for external data base access

CSCvr04954

FMC 6.4.0 - Stack unit on different Domain fails the deployment after upgrade

CSCvr07421

Policy deployment fails with 400+ interfaces in security zone due to incorrect formation of deployDB

CSCvr10777

ASA Traceback in Ikev2 Daemon

CSCvr11395

Only a subset of devices where deployed from a device group during scheduled deploy

CSCvr12018

ASA: VPN traffic fails to take the tunnel route when the default route is learnt over BGP.

CSCvr23580

Can't delete 2 or more than two IP address-pool

CSCvr25954

FTD/LINA Standby may traceback and reload during logging command replication from Active

CSCvr27445

App-sync failure if unit tries to join HA during policy deployment

CSCvr29638

HA FTD on FPR2110 crash after deploy ACP from FMC

CSCvr35956

Block double-free when combining ServerKeyExchange and ClientKeyExchange fails --> lina crashes

CSCvr36687

Overrides cannot be added for network object if it is used in variable sets in sub domains

CSCvr37486

established rules in asp table are not un-installed on config removal

CSCvr44123

Unable to login via chassis Manager or Rest api in FPR2100 if session timeout is non-deafult

CSCvr95287

Cisco Firepower Management Center LDAP Authentication Bypass Vulnerability