CSCvf88062
|
CTM: Nitrox S/G lengths need to be validated
|
CSCvg69380
|
ASA - rare cp processing corruption causes console lock
|
CSCvh19737
|
HTTPS access on FTD data interface (off-box management) is
failing
|
CSCvi96835
|
No validation err when changing host thats part of a group object
used in a routing policy, to Range
|
CSCvj08826
|
FMC ibdata1 file might grow large in size
|
CSCvm82290
|
ASA core blocks depleted when host unreachable in IRB/TFW
configuration
|
CSCvo34210
|
ASA running 9.6.4.20 Traceback in threadname Unicorn Proxy
Thread
|
CSCvp13352
|
ASA continues to do TCP keepalives for Client side connections
even after vpn session times out
|
CSCvp15559
|
Traceback on secondary ASA during config synchronisation
|
CSCvp28713
|
Input/Output interfaces in packet tracer RESULT are shown as
"UNKNOWN"
|
CSCvp69936
|
ASA : Traceback on tcp_intercept Thread name : Threat
detection
|
CSCvq98396
|
ASA: crypto session handles leak on the standby unit
|
CSCvr11958
|
AWS FTD: Deployment failure with ERROR: failed to set interface
to promiscuous mode
|
CSCvr33428
|
FMC generates Connection Events from a SYN flood attack
|
CSCvr77005
|
Traffic does not fallback to primary interface from crypto map
when interface becomes available
|
CSCvr85295
|
Cisco Adaptive Security Appliance Software and Firepower Threat
Defense Software Remote
|
CSCvs13204
|
ASAv failover traffic on SR-IOV interfaces might be dropped due
to interface-down
|
CSCvs50538
|
Firewall engine should fall back on info from SSL handshake if
SSL engine is not returning a verdict
|
CSCvs72390
|
Cisco Firepower Management Center Cross-Site Scripting
Vulnerability
|
CSCvs72450
|
FXOS - Recover hwclock of service module from corruption due to
simultaneous write collision
|
CSCvs74802
|
AnyConnect/S2S IKEv2 crypto policy occasionally not deployed to
device
|
CSCvs82926
|
Critical RPM alert on FRP 1000 and FPR2100 Series with ASA
'Chassis 0 Cooling Fan OK' SCH message
|
CSCvs84542
|
ASA traceback with thread: idfw_proc
|
CSCvs95188
|
FXOS FTD Multi Instance CPU cores shared between different
instances
|
CSCvt10944
|
ctm crashed while sending emix traffic over VTI tunnel
|
CSCvt11885
|
Running the migration script exits with an out of memory
error
|
CSCvt37303
|
Prefilter Rule zone validation (activity validation) is bypassed
in HW layer for UI
|
CSCvt39977
|
Invalid packet data when PSNG_TCP_PORTSCAN [122:1:1] rule
alerts.
|
CSCvt48260
|
Standby unit traceback at fover_parse and boot loop when
detecting Active unit
|
CSCvt52604
|
Interfaces page from Objects section of the FMC does not load
(domains page is likely affected also)
|
CSCvt55927
|
Unable to break HA in 6.4.0.9-34 FDM
|
CSCvt71529
|
ASA traceback and reload during SSL handshake
|
CSCvt74194
|
Error getting unified2 record: Corrupt file
|
CSCvt75760
|
Traceback/Page-fault in Clientless WebVPN due to HTTP cleanup
|
CSCvt92077
|
Ping Failure on ASAv - 9.13 after CAT9k reboot
|
CSCvt97205
|
SNMPPOLL/SNMPTRAP to remote end (site-to-site vpn) ASA interface
fails on ASA 9.14.1
|
CSCvu02594
|
Snort taking long time to terminate, because of too many async
sessions
|
CSCvu09496
|
DNS data collected and exported multiple times while same DNS
policy referenced in many ACP's
|
CSCvu18510
|
MonetDB's eventdb crash causes loss of connection events on
FMC 6.6.0 and 6.6.1
|
CSCvu30704
|
ASA traceback with crashinfo of size "0"
|
CSCvu33992
|
traceback: ASA reloaded lina_sigcrash+1394
|
CSCvu44472
|
FMC System processes are starting
|
CSCvu75855
|
stunnel process enabled on managed device when it should not
be
|
CSCvu77689
|
FTP to FileZilla miscategorized as SMTP
|
CSCvu82680
|
Some performance files are included as part of FTD Backup which
should not be
|
CSCvu84127
|
Firepower may reboot for no apparent reason
|
CSCvu87906
|
Backup file keep growing in 6.6.0-90 (Unified Event Files are
Incorrectly Included In Backup)
|
CSCvu89110
|
ASA: Block new conns even when the "logging
permit-hostdown" is set & TCP syslog is down
|
CSCvu94878
|
The client side in OpenSSH 5.7 through 8.3 has an Observable
Discrepan
|
CSCvu97112
|
SNMP polling stopped working on active device in HA
|
CSCvu97242
|
2100: Corefile and crashinfo might both be truncated and
incomplete in the event of a crash
|
CSCvu98222
|
FTD Lina engine may traceback in datapath after enabling SSL
decryption policy
|
CSCvv00719
|
Access Control Policy with time range object is not getting
hit
|
CSCvv02925
|
OSPF neighbourship is not establising
|
CSCvv07917
|
ASA learning a new route removes asp route table created by
floating static
|
CSCvv10778
|
Traceback in threadname DATAPATH (5585) or Lina (2100) after
upgrade to 9.12.4
|
CSCvv15572
|
ASA traceback observed when "config-url" is entered
while creating new context
|
CSCvv17585
|
Netflow template not sent under certain circumstances
|
CSCvv19230
|
ASAv Anyconnect users unexpectedly disconnect with reason: Idle
Timeout
|
CSCvv20780
|
Policy deploy fails with "Failed to hold the deployment
transaction" error
|
CSCvv24647
|
FP2100 - SNMP: incorrect values returned for Ethernet statistics
polling
|
CSCvv24976
|
Static default route is not installed in the rib after shutdown
the RRI route interface
|
CSCvv25394
|
After upgrade ASA swapped names for disks, disk0 became disk1 and
vice versa.
|
CSCvv30172
|
Intermittently after reboot, ADI can't join KCD
|
CSCvv31755
|
Interface status may be mismatched between application and
chassis due to missed update
|
CSCvv32333
|
ASA still doesn't allow to poll internal-data0/0 counters via
SNMP in multiple mode
|
CSCvv36788
|
MsgLayer[PID]: Error : Msglyr::ZMQWrapper::registerSender() :
Failed to bind ZeroMQ Socket
|
CSCvv37629
|
Malformed SIP packets leads to 4k block hold-up till SIP conn
timeout causing probable traffic issue
|
CSCvv40406
|
FTD/ASA creates coredump file with "!" character in
filename (lina changes).
|
CSCvv41453
|
Removing static ipv6 route from management-only route table
affects data traffic
|
CSCvv44863
|
Failure to load default threat category setting from URL
filtering configuration file
|
CSCvv49698
|
ASA Anyconnect url-redirect not working for ipv6
|
CSCvv49800
|
ASA/FTD: HA switchover doesn't happen with graceful reboot of
firepower chassis
|
CSCvv50338
|
Traceback Cluster unit on snpi_nat_xlate_destroy+2508
|
CSCvv52349
|
No utility to handle XFS corruption on 2100/1000 series Firepower
devices
|
CSCvv52591
|
DMA memory leak in ctm_hw_malloc_from_pool causing management and
VPN connections to fail
|
CSCvv53696
|
ASA/FTD traceback and reload during AAA or CoA task of Anyconnect
user
|
CSCvv55248
|
Syslogs generated for ACL transaction commit are not in
consistent format & not available some times
|
CSCvv55291
|
Snmp user fails on standby device after rejoing ha, after ha
break.
|
CSCvv56644
|
Cisco Adaptive Security Appliance Software and Firepower Threat
Defense Software Web DoS
|
CSCvv58332
|
ASA/FTD is reading BGP MP_REACH_NLRI attribute's next-hop
bytes in reverse order
|
CSCvv62305
|
ASA traceback and reload in fover_parse when attempting to join
the failover pair.
|
CSCvv63412
|
ASA dropping all traffic with reason "No route to host"
when tmatch compilation is ongoing
|
CSCvv64068
|
After modify network/service object name. mis-match will occur on
hash value of ACL in syslog.
|
CSCvv65184
|
Cisco Adaptive Security Appliance Software and Firepower Threat
Defense Software Web DoS
|
CSCvv66005
|
ASA traceback and reload on inspect esmtp
|
CSCvv66561
|
The key-string support under ssh pubkey-chain server is not
working as intended.
|
CSCvv66920
|
Inner flow: U-turn GRE flows trigger incorrect connection flow
creation
|
CSCvv67196
|
FTD does not try all the crl urls for getting crl file
|
CSCvv67398
|
Inspect-snmp drops thru-the-box snmp paks if snmp is disabled
|
CSCvv67500
|
ASA 9.12 random traceback and reload in DATAPATH
|
CSCvv68669
|
Traffic to virtual IP address dropped on system context of Master
ASA due to failed classification
|
CSCvv69991
|
FTD stuck in Maintenance Mode after upgrade to 6.6.1
|
CSCvv70984
|
ASA traceback while modifying the bookmark SSL Ciphers
configuration
|
CSCvv71097
|
traceback: ASA reloaded snp_fdb_destroy_fh_callback+104
|
CSCvv72466
|
OSPF network commands go missing in the startup-config after
upgrading the ASA
|
CSCvv73017
|
Traceback due to fover and ssh thread
|
CSCvv74658
|
FTD/ASA creates coredump file with "!" character in
filename (zmq changes (fxos) for CSCvv40406 )
|
CSCvv79897
|
Block "sensor restart" command for FTD units to prevent
Lina crash and system reboot event
|
CSCvv80782
|
Traceback leads to the purg_process
|
CSCvv85029
|
ASA5555 traceback and reload on Thread Name: ace_work
|
CSCvv86861
|
Traceback during SNMP traffic testing
|
CSCvv86926
|
Unexpected traceback and reload on FTD creating a Core file
|
CSCvv87232
|
ASA: High number of CPU hog in igb_saleen_io_sfp_mod_poll_thread
process
|
CSCvv87496
|
ASA cluster members 2048 block depletion due to "VPN packet
redirect on peer"
|
CSCvv88017
|
ASA: EasyVPN HW Client triggers duplicate phase 2 rekey causing
disconnections across the tunnel
|
CSCvv89355
|
DHCP-Proxy renewal timer is not started after failover
|
CSCvv89400
|
ASA SNMPv3 Poll fails when using AES 256
|
CSCvv89708
|
ASA/FTD may traceback in thread name fover_FSM_thread and
reload
|
CSCvv89715
|
Fastpath rules for 8000 series stack disappear randomly from the
FMC
|
CSCvv90079
|
No router BGP pushed after making chnages on 9300 intra chassis
cluster
|
CSCvv90181
|
No deployment failure reason in transcript if 'show
running-config' is running during deployment
|
CSCvv90720
|
ASA/FTD: Mac address-table flap seen on connected switch after a
HA switchover
|
CSCvv90753
|
Syncd process hangs due to SLA
|
CSCvv94165
|
FTD 6.6 : High CPU spikes on snmpd process
|
CSCvv94701
|
ASA keeps reloading with "octnic_hm_thread". After the
reload, it takes very long time to recover.
|
CSCvv96193
|
ASA/FTD debugs do not print clear failure reason when no proposal
is chosen
|
CSCvv97527
|
asa config timeout command breaks snort's DAQ
configuration
|
CSCvv97877
|
Secondary unit not able to join the cluster
|
CSCvw00161
|
ASA traceback and reload due to VPN thread on firepower 2140
|
CSCvw01767
|
CRL fail-open option may not work depending on hierarchy
|
CSCvw03628
|
ASA will not import CA certificate with name constraint of
RFC822Name set as empty
|
CSCvw05392
|
Message appearing constantly on diagnostic-cli
|
CSCvw06195
|
ASA traceback cp_midpath_process_thread
|
CSCvw06298
|
ASA duplicate MAC addresses in Shared Interfaces of different
Contexts causing traffic impact
|
CSCvw07000
|
Snort busy drops with PDTS Tx queue stuck
|
CSCvw12008
|
ASA traceback and reload while executing "show
tech-support" command
|
CSCvw12040
|
Heapcache Memory depleting rapidly due to certificate chain
failed validation
|
CSCvw12100
|
ASA stale VPN Context seen for site to site and AnyConnect
sessions
|
CSCvw13348
|
WR6, WR8 and LTS18 commit id update in CCM layer (sprint 98, seq
2)
|
CSCvw15359
|
KP fxos snmp has uninit strings for
entPhysicalSerialNum,entPhysicalAssetID on EPM index
|
CSCvw16165
|
Firepower 1010 Series stops passing traffic when a member of the
port-channel is down
|
CSCvw16619
|
Offloaded traffic not failed over to secondary route in ECMP
setup
|
CSCvw18614
|
ASA traceback in the LINA process
|
CSCvw19227
|
Unable to remove non-used prefix-list object
|
CSCvw19907
|
restart of snmpd for agx communication fail to snmp-sa
|
CSCvw21145
|
Duplicate NAT rule error when saving the policy (caused by
duplicate Auto NAT rules)
|
CSCvw21161
|
Duplicate NAT rule error when saving the policy (different rules
are detected as duplicates)
|
CSCvw21844
|
FTD traceback and reload on DATAPATH thread when processing
encapsulated flows
|
CSCvw22576
|
"no mfib forwarding" command on state fover interface
on standby only
|
CSCvw22881
|
radius_rcv_auth can shoot up control plane CPU to 100%.
|
CSCvw22986
|
Secondary unit stuck in Bulk sync infinitely due to interface of
Primary stuck in init state
|
CSCvw23199
|
ASA/FTD Traceback and reload in Thread Name: Logger
|
CSCvw24556
|
TCP File transfer (Big File) not properly closed when Flow
offload is enabled
|
CSCvw26171
|
ASA syslog traceback while strncpy NULL string passed from SSL
library
|
CSCvw26331
|
ASA traceback and reload on Thread Name: ci/console
|
CSCvw26544
|
Cisco ASA and FTD Software SIP Denial of Service
Vulnerability
|
CSCvw27301
|
IKEv2 with EAP, MOBIKE status fails to be processed.
|
CSCvw28814
|
SNMP process crashed, resulting in Lina traceback
|
CSCvw30252
|
ASA/FTD may traceback and reload due to memory corruption in
SNMP
|
CSCvw31569
|
Director/Backup flows are left behind and traffic related to this
flow is blackholed
|
CSCvw32518
|
ASASM traceback and reload after upgrade up to 9.12(4)4 and
higher
|
CSCvw36662
|
TACACS+ ASCII password change request not handled properly
|
CSCvw37259
|
VPN syslogs are generated at a rate of 600/s until device goes
into a hang state
|
CSCvw37340
|
Vulnerability in the MySQL Server product of Oracle MySQL
(component:
|
CSCvw37807
|
Ipsec Send Error Increasing When NTP Authenticate is Enabled
|
CSCvw42091
|
FTD/HA: "no shutdown" command disappear from
running-config of standby
|
CSCvw42999
|
9.10.1.11 ASA on FPR2110 traceback and reloads randomly
|
CSCvw43486
|
ASA/FTD Traceback and reload during PBR configuration change
|
CSCvw43489
|
The NEEDBITS macro in the inflate_dynamic function in inflate.c
for ...
|
CSCvw43508
|
Heap-based buffer overflow in the CRC32 verification in Info-ZIP
UnZ ...
|
CSCvw43510
|
Heap-based buffer overflow in the test_compr_eb function in
Info-ZIP ...
|
CSCvw43529
|
Integer overflow in the DHCP client (udhcpc) in BusyBox before
1.25. ...
|
CSCvw43534
|
A Null pointer dereference vulnerability exists in Mozilla
Network S ...
|
CSCvw43537
|
The recv_and_process_client_pkt function in networking/ntpd.c in
bus ...
|
CSCvw43541
|
inftrees.c in zlib 1.2.8 might allow context-dependent attackers
to ...
|
CSCvw43543
|
The inflateMark function in inflate.c in zlib 1.2.8 might allow
cont ...
|
CSCvw43544
|
The crc32_big function in crc32.c in zlib 1.2.8 might allow
context- ...
|
CSCvw43546
|
In the add_match function in libbb/lineedit.c in BusyBox through
1.2 ...
|
CSCvw43555
|
A heap-based buffer overflow exists in Info-Zip UnZip version
<= 6.0 ...
|
CSCvw43559
|
BusyBox project BusyBox wget version prior to commit
8e2174e9bd836e5 ...
|
CSCvw43567
|
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a
file ...
|
CSCvw43571
|
An issue was discovered in BusyBox before 1.30.0. An out of
bounds r ...
|
CSCvw43586
|
A vulnerability was found in gnutls versions from 3.5.8 before
3.6.7 ...
|
CSCvw43615
|
An issue was discovered in GnuTLS before 3.6.15. A server can
trigge ...
|
CSCvw44122
|
ASA: "class-default" class-map redirecting non-DNS
traffic to DNS inspection engine
|
CSCvw45863
|
ASAv snmp traceback on reload
|
CSCvw46630
|
FTD: NLP path dropping return ICMP destination unreachable
messages
|
CSCvw46702
|
FTD Cluster secondary units fail to join cluster due to
application configuration sync timeout
|
CSCvw47321
|
IPSec transport mode traffic corruption for inbound traffic for
some FPR platforms
|
CSCvw48517
|
DAP stopped working after upgrading the ASA to 9.13(1)13
|
CSCvw48829
|
Timezone in "show clock" is different from which in
"show run clock"
|
CSCvw50679
|
ASA/FTD may traceback and reload during upgrade
|
CSCvw51307
|
ASA/FTD traceback and reload in process name "Lina"
|
CSCvw51462
|
IPv4 Default Tunneled Route Rejected
|
CSCvw51745
|
RIP database not populated with SLA monitored static route that
was re added in the routing table.
|
CSCvw51950
|
FPR SSL trust-point removed from new active ASA after manual
Failover
|
CSCvw51985
|
ASA: AnyConnect sessions cannot be resumed due to ipv6 DACL
failure
|
CSCvw52083
|
The FXOS logrotate does not rotate properly all the log files
|
CSCvw52609
|
Cisco ASA and FTD Software Web Services Buffer Overflow Denial of
Service Vulnerability
|
CSCvw53255
|
FTD/ASA HA: Standby Unit FXOS is still able to forward traffic
even after failover due to traceback
|
CSCvw53427
|
ASA Fails to process HTTP POST with SAML assertion containing
multiple query parameters
|
CSCvw53796
|
Cisco ASA and FTD Web Services Interface Cross-Site Scripting
Vulnerability
|
CSCvw54640
|
FPR-4150 - ASA traceback and reload with thread name DATAPATH
|
CSCvw56703
|
IPv6 static routes not getting installed, upon changing ifc type
management-only
|
CSCvw58414
|
Name of anyconnect custom attribute of type
dynamic-split-exclude-domains is changed after reload
|
CSCvw59035
|
Connection issues to directly connected IP from FTD BVI
address
|
CSCvw60177
|
Standby/Secondary cluster unit might crash in Thread Name:
fover_parse and "cluster config sync"
|
CSCvw62526
|
ASA traceback and reload on engineering ASA build -
9.12.3.237
|
CSCvw62528
|
ASA failing to sync with IPv6 NTP server
|
CSCvw63862
|
ASA: Random L2TP users cannot access resources due to stale ACL
filter entries
|
CSCvw64623
|
Standby ASA linkdown SNMPtrap sent from standby interface with
active IP address
|
CSCvw68593
|
A flaw in the way reply ICMP packets are limited in the Linux
kernel f
|
CSCvw71766
|
ASA traceback and reload in Thread: Ikev2 Daemon
|
CSCvw72260
|
ASA upgrade failed with: "CSP directory does not exist -
STOP_FAILED Application_Not_Found"
|
CSCvw72608
|
Failed event for standby received on Active causes future
deployments to be skipped on standby
|
CSCvw73402
|
Failed cluster copy capture to remote FTP renders the FTD LINA
CLI unresponsive
|
CSCvw74940
|
ASA traceback in IKE Daemon and reload
|
CSCvw75104
|
Deployment failure on FDM-HA for port channel member interface
changes
|
CSCvw75605
|
Connection Events Table View report fails when Domain, Count and
any other field are selected.
|
CSCvw77930
|
ASA fails to process SAML assertion when tunnel-group name
contains "."
|
CSCvw79208
|
Incorrect URL normalization when "http://" substring is
at a latter stage in the input string
|
CSCvw79294
|
sftunnel logging huge number of logs to messages file
|
CSCvw81322
|
FTD running multi-instance mode gets snort GID 3 rules disabled
after SRU install and deploy
|
CSCvw81897
|
ASA: OpenSSL Vulnerability CVE-2020-1971
|
CSCvw82577
|
Many small files as part of the Monet DB bloats up the size of
the FMC backup tar file
|
CSCvw82629
|
ASA Tracebacks when making "configuration session"
changes regarding an ACL.
|
CSCvw83572
|
BVI HTTP/SSH access is not working in versions 9.14.1.30 or
above
|
CSCvw83665
|
Unable to deploy changes on FTD managed by FDM, post upgrade
|
CSCvw83780
|
FTD Firewall may traceback and reload when modifying ACLs
|
CSCvw84339
|
Managed device backup fails, for FTD, if hostname exceeds 30
characters
|
CSCvw84786
|
ASA traceback and reload on Thread name snmp_alarm_thread
|
CSCvw87788
|
ASA traceback and reload webvpn thread
|
CSCvw88176
|
MonetDB eventdb crash causes loss of connection events on FMC
6.6.1
|
CSCvw89365
|
ASA/FTD may traceback and reload during certificate changes.
|
CSCvw90151
|
PPPOE - ASA sends CONFACK for non-configured protocol
|
CSCvw90634
|
FP2100 ASA - 1 Gbps SFP in network module down/down after upgrade
to 9.15.1.1
|
CSCvw91757
|
NAP dropping SNMPv3 traffic passing through FTDv after upgrade to
6.6.1
|
CSCvw93139
|
Cisco ASA and FTD Software for FP 1000/2100 Series Command
Injection Vulnerability
|
CSCvw94988
|
S2S traffic fails due to missing V routes after Primary cluster
unit gets disabled
|
CSCvw95301
|
ASA traceback and reload with Thread name: ssh when capture was
removed
|
CSCvw96129
|
[IMS_7_0_0] Deploy after HA break fails on secondary with Lina
Write Memory failed
|
CSCvw96488
|
Traceback in inspect_h323_ras+1810
|
CSCvw97256
|
Need handling of rmu read failure to ignore link state update
when link state API read fails
|
CSCvw97267
|
DHCP client new IP address acquisition fails whenever there is a
switchport flap
|
CSCvw97821
|
ASA: VPN traffic does not pass if no dACL is provided in CoA
|
CSCvw98315
|
FXOS reporting old FTD version after FTD upgrade to 6.7.0
|
CSCvw98603
|
Multiple vulnerabilities in SQlite
|
CSCvw98840
|
ASA: dACL with no IPv6 entries is not applied to v6 traffic after
CoA
|
CSCvw99916
|
ASAv: SNMP result for used memory value incorrect after upgrade
to 9.14
|
CSCvx00655
|
ASA/SFR service card failure due to timeout getting
CriticalStatus from PM
|
CSCvx01805
|
AppAgent gets deregistered due to hearbeat failure during config
sync up on Firepower 2100s
|
CSCvx02869
|
Traceback in Thread Name: Lic TMR
|
CSCvx03764
|
Offload rewrite data needs to be fixed for identity nat traffic
and clustering environment
|
CSCvx04057
|
When SGT name is unresolved and used in ACE, line is not being
ignored/inactive
|
CSCvx04643
|
ASA reload is removing 'content-security-policy'
config
|
CSCvx05381
|
Cisco ASA and FTD Software Command Injection Vulnerability
|
CSCvx05385
|
ASA may generate a traceback in Logger thread during
configuration sync in HA
|
CSCvx05956
|
High snort cpu usage while copying navl attribute
|
CSCvx06385
|
Fail-to-wire ports in FPR 2100 flapping after upgrade to
6.6.1
|
CSCvx08734
|
ASA: default IPv6/IPv4 route tunneled does not work
|
CSCvx09147
|
sftunnel fsync does not handle empty files and shows memory
leak
|
CSCvx09248
|
SNMP walk for v2 and v3 fails with No Such Object available on
this agent at this OID is seen
|
CSCvx09535
|
ASA Traceback: CRL check for an Anyconnect client with a revoked
certificate triggers reload
|
CSCvx10110
|
Last transaction timestamp status "unknown" for active
LDAP AAA server
|
CSCvx10502
|
In drivers/target/target_core_xcopy.c in the Linux kernel before
5.10.
|
CSCvx10514
|
An issue was discovered in p11-kit 0.21.1 through 0.23.21.
Multiple in
|
CSCvx10519
|
curl 7.62.0 through 7.70.0 is vulnerable to an information
disclosure
|
CSCvx10520
|
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction
of na
|
CSCvx10555
|
A flaw was found in ImageMagick in MagickCore/statistic.c. An
attacker
|
CSCvx10841
|
Not able to Advertise/Redistribute VXLAN/VNI interface subnet
using EIGRP
|
CSCvx11295
|
ASA may traceback and reload on thread Crypto CA
|
CSCvx11460
|
Firepower 2110 silently dropping traffic with TFC enabled on the
remote end
|
CSCvx13694
|
ASA/FTD traceback in Thread Name: PTHREAD-4432
|
CSCvx13835
|
Multiple vulnerabilities in bind
|
CSCvx14031
|
IPv4 DACL stuck on Active device when DACL removed after CoA for
IKEv2 Session, traffic not impacted
|
CSCvx15040
|
DHCP Proxy Offer is getting drop on the ASA/FTD
|
CSCvx16202
|
self referenced object pushed from FMC results in lina crash with
error - loop in grp hierarchy
|
CSCvx16317
|
Failure accessing FXOS with connect fxos admin from Multi-Context
ASA if admin context is changed
|
CSCvx16592
|
FTD doesn't redirect packets to the WCCP web-cache engine
when VRF's are configured
|
CSCvx16700
|
FXOS clock sync issue during blade boot up due to "MIO DID
NOT RESPOND TO FORCED TIME SYNC"
|
CSCvx17664
|
ASA may traceback and reload in Thread Name
'webvpn_task'
|
CSCvx17780
|
FPR-2100-ASA : SNMP Walk for ifType is showing "other"
for ASA interfaces in the latest versions
|
CSCvx17785
|
Traceback seen when adding/removing acl & entering into
route-map command (pbr_route_map_update)
|
CSCvx17842
|
Prevent lina from traceback due to object loop sent by FMC. Fail
the deployment instead.
|
CSCvx19934
|
Deployment gets failed for snmp settings while deleting snmpv1
and adding snmpv3 at a time in 6.6.3
|
CSCvx20303
|
ASA/FTD may traceback in after changing snmp host-group
object
|
CSCvx20692
|
Only ten objects are seen under Smart CLI when all objects have
the same type
|
CSCvx20872
|
ASA/FTD Traceback and reload due to netflow refresh timer
|
CSCvx21782
|
Firepower platforms generate corrupted coredump due to lina
monitor
|
CSCvx22695
|
ASA traceback and reload during OCSP response data cleanup
|
CSCvx23833
|
IKEv2 rekey - Invalid SPI for ESP packet using new SPI received
right after Create_Child_SA response
|
CSCvx23907
|
Evaluate the impact of NGFW for CVE-2021-1405
|
CSCvx24537
|
SAML: SAML Authentication may fail if we have 2 or more IDP certs
with same Subject Name
|
CSCvx25406
|
LINA silently drops packet if the MTU of the packet is of size
> the MTU of egress interface
|
CSCvx25719
|
X-Frame-Options header is not set in webvpn response pages
|
CSCvx25836
|
ASA traceback & reload due to "show crashinfo"
adding a new output log
|
CSCvx26221
|
Traceback into snmp at handle_agentx_packet / snmp takes long
time to come up on FP1k and 5508
|
CSCvx26308
|
ASA traceback and reload due to strcpy_s: source string too long
for dest
|
CSCvx26525
|
FMC was upgraded to 6.6.1 Post this we noticed that on FTD
Devices - snmp configuration is missing
|
CSCvx26808
|
FTD traceback and reload on process lina on FPR2100 series
|
CSCvx26927
|
TLS site not loading when it has segmented and retransmitted
CH
|
CSCvx27077
|
SAML: Prevent webvpn saml IDP config removal when it is
referenced under tunnel-group
|
CSCvx27430
|
ASA: Unable to import PAC file if FIPS is enabled.
|
CSCvx27914
|
Unable to see events under Geolocation widgets FMC
|
CSCvx28520
|
SSL decryption failure using customer SSL rule with DKK
|
CSCvx29429
|
ma_ctx*.log consuming high diskspace on FPR4100/FPR9300 despite
the fix for CSCvx07389
|
CSCvx29448
|
FTD: SNMP host configured with diagnostic int able to poll
management int
|
CSCvx29771
|
Firewall CPU can increase after a bulk routing update with flow
offload
|
CSCvx29814
|
IP address in DHCP GIADDR field is reversed after sending DHCP
DECLINE to DHCP server
|
CSCvx29832
|
CPU performance degrade with lots of route updates with flow
offload enabled
|
CSCvx30314
|
ASA traceback and reload in ssl midpath
|
CSCvx33822
|
No option to deploy ASAv with 4gb RAM and 2 CPU
|
CSCvx33904
|
Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing
privile
|
CSCvx34237
|
ASA reload with FIPS failure
|
CSCvx34335
|
AAA LDAP Server: Average round trip time is always 0ms
|
CSCvx37737
|
HA failure due to OSPF NSF after HA break and upgrade to
6.6.0/6.6.1
|
CSCvx38124
|
Core-local block alloc failure on cores where CP is pinned
leading to drops
|
CSCvx41171
|
Concurrent modification of ACL configuration breaks output of
"show running-config" completely
|
CSCvx41440
|
URL reputation mismatch between Talos cloud and local DBs.
|
CSCvx42081
|
FPR4150 ASA Standby Ready unit Loops to failed and remove config
to install it again
|
CSCvx42197
|
ASA EIGRP route stuck after neighbour disconnected
|
CSCvx44117
|
Addition of new net-snmp patches and cleaning up unused net-snmp
recipes
|
CSCvx44401
|
FTD/ASA traceback in Thread Name : Unicorn Proxy Thread
|
CSCvx45976
|
ASA/FTD Watchdog forced traceback and reload in Threadname:
vnet-proxy (rip: socks_proxy_datarelay)
|
CSCvx47230
|
X-Frame-Options header support for older versions of IE and
windows platforms
|
CSCvx47628
|
In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an
assertion
|
CSCvx47634
|
The iconv function in the GNU C Library (aka glibc or libc6) 2.32
and
|
CSCvx47642
|
An integer underflow was discovered in OpenLDAP before 2.4.57
leading
|
CSCvx48490
|
SSL Decrypted https flow EOF events showing
'Initiator/Responder' Packets as 0
|
CSCvx49715
|
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and
EVP_DecryptUpdate may
|
CSCvx49716
|
An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x
before
|
CSCvx49720
|
BIND servers are vulnerable if they are running an affected
version an
|
CSCvx50366
|
Traceback in Thread Name: fover_health_monitoring_thread
|
CSCvx52122
|
ASA traceback and reload in SNMP Notify Thread while deleting
transparent context
|
CSCvx54235
|
ASP capture dispatch-queue-limit shows no packets
|
CSCvx54396
|
Intermittent policy deployment failure when multicast routing is
enabled
|
CSCvx54606
|
FTD 6.6.1/6.7.0 is sending SNMP Ifspeed OID (1.3.6.1.2.1.2.2.1.5)
response value = 0
|
CSCvx54934
|
Intrusion Event Report Generation fails when using Inline Result
with graph format
|
CSCvx56323
|
Edit of S2S VPN fails with error "Node not found:
12884908935"
|
CSCvx57417
|
Smart Tunnel Code signing certifcate renewal
|
CSCvx59120
|
COA Received before data tunnel comes up results in tear down of
parent session
|
CSCvx61200
|
TID feeds stuck due to references leak
|
CSCvx62239
|
Need comprehensive details in logs on what is stopping VPN
load-balancing cluster formation
|
CSCvx63256
|
Error when entering expert mode on FTD/ 4110 after upgrade to
6.6.3 from 6.2.3
|
CSCvx63647
|
ASA traceback and reload on Thread Name: CTM Daemon
|
CSCvx64478
|
Unwanted console output during SAML transactions
|
CSCvx65467
|
663 FDM not sending syslog events after configuration changes
|
CSCvx65745
|
FPR2100: enable kernel panic on octeon for UE events to trigger
crash
|
CSCvx67996
|
FMC RAVPN: Deployment is failing when IPv6 DNS is configured
under Group Policy
|
CSCvx68128
|
ASA internal deadlock leads to loss of feature functionality
(syslogs, reload, ASDM, anyconnect)
|
CSCvx68355
|
ASA - unable to import CA certificate when countryName is encoded
as UTF8
|
CSCvx68490
|
FDM upgrade fails on 100_ftd_onbox_data_import.sh due to deleted
SSL URL categories
|
CSCvx68951
|
ASA responds with "00 00 00 00 00 00" when polling
interface physical address using snmp
|
CSCvx69405
|
ASA Traceback and reload in Thread Name: SNMP ContextThread
|
CSCvx71434
|
ASA/FTD Traceback and reload in Thread Name: pix_startup_thread
due to asa_run_ttyS0 script
|
CSCvx71571
|
ASA: "ERROR: Unable to delete entries from Hash Table"
with CSM
|
CSCvx72904
|
Optimise ifmib polls
|
CSCvx73164
|
Lasso SAML Implementation Vulnerability Affecting Cisco Products:
June 2021
|
CSCvx74035
|
ASA traceback and reload after run "clear configure
all" with multiple ACLs and objects configured
|
CSCvx75503
|
Re-transmitted SYN are not inspected by inspection engine
|
CSCvx75963
|
ASA traceback while taking captures
|
CSCvx76703
|
FMC won't save prefilter policy changes if a rule is matching
traffic by Interface Group
|
CSCvx77768
|
Traceback and reload due to Umbrella
|
CSCvx78238
|
multi context Firepower services on ASA traffic goes to incorrect
interfaces
|
CSCvx79793
|
Slow file transfer or file upload with SSL policy is applied with
Decrypt resign action
|
CSCvx80835
|
Manual enrollment creates stuck pending trustpoint entry in LINA
after importing certificate
|
CSCvx81405
|
Connections expected to match known key rules may not be
decrypted
|
CSCvx85534
|
SNMP traps being sent out sourced with unexpected IP from the
data interface
|
CSCvx85922
|
ASA/FTD may traceback and reload when saving/writitng the
configuration to memory
|
CSCvx86177
|
inet6_ntoa and unix_timestamp Functions used to externally poll
FMC database return errors
|
CSCvx87679
|
Failover license count not synced to standby firewall.
|
CSCvx87709
|
FPR 2100 running ASA in HA. Traceback and reload on watchdog
during failover
|
CSCvx87790
|
FPR 2100 running ASA in HA. Traceback and reload on watchdog
during failover
|
CSCvx88683
|
ASA not replicating BGP password correctly to standby unit
|
CSCvx89827
|
Not able to set Bangkok time zone in FPR 2110
|
CSCvx91341
|
An issue was discovered in GNOME GLib before 2.66.8. When
g_file_repla
|
CSCvx94326
|
VPN Load Balancing may get stuck and disconnect from the
group
|
CSCvx94398
|
Secondary ASA could not get the startup configuration
|
CSCvx95255
|
Supportive change in ASA to differentiate, new ASDM connections
from existing ASDM context switch
|
CSCvx97632
|
ASA traceback and reload when copying files with long destination
filenames using cluster command
|
CSCvx98041
|
FTD-API: ruleId duplicate sequence number causes invalid snort
ngfw.rules to be deployed
|
CSCvx99373
|
FMC: "beakerd" process core files not archiving debug
symbols hence unusable
|
CSCvy01752
|
Traceback on FPR 4115 in Thread - Lic HA Cluster
|
CSCvy02448
|
Time sync do not work correctly for ASA on FPFPR2100 series
platform
|
CSCvy02703
|
ASA/FTD tracebacks due to CTM message handler
|
CSCvy03006
|
improve debugging capability for uauth
|
CSCvy03045
|
Failure accessing FXOS with connect fxos admin from Multi-Context
ASA if admin context is changed
|
CSCvy03907
|
Creation/Edit of Access Control Policy fails with error 'Rule
Name Already Exists'
|
CSCvy04869
|
AnyConnect certificate authentication fails if user certificate
has 8192 bits key size
|
CSCvy04965
|
WM Standby fails to re-join HA with msg "CD App Sync error
is Failed to apply SSP config on standby"
|
CSCvy05807
|
Observed SNMPWalk Failure after FO Sync operation.
|
CSCvy05966
|
Snort 2.9.16.3-3033 traceback (FTD 6.6.3)
|
CSCvy07491
|
ASA traceback when re-configuring access-list
|
CSCvy07654
|
FTD: Failover role change when generating TS files due to after
ndclientd missing heartbeats
|
CSCvy08908
|
Port-forwarding application blocked by Java
|
CSCvy09217
|
HA goes to active-active state due to cipher mismatch
|
CSCvy09252
|
Syncd exits repeatedly on secondary FMC part of FMC HA
|
CSCvy10665
|
Firepower 9000 Series SM-56 missing filespec entry for YYYY-MM-DD
files in diskmanager
|
CSCvy13229
|
FDM - GUI Inaccessible - tomcat is opening too many file
descriptors
|
CSCvy17365
|
REST API Login Page Issue
|
CSCvy17470
|
ASA Traceback and reload on the A/S failover pair at IKEv2.
|
CSCvy19453
|
SFDataCorrelator performance problems involving redundant new
host events with only MAC addresses
|
CSCvy30016
|
"Max cert cache entries" pruning needs to lock the ssl
cache
|
CSCvy34333
|
When ASA upgrade fails, version status is desynched between
platform and application
|
CSCvy37835
|
ssl replace key only action can cause unbounded detection engine
memory usage
|
CSCvy39191
|
An internal server error 500 in T-ufin when doing API calls to
the FMC
|
CSCvy39659
|
ASA/FTD may traceback and reload in Thread Name
'DATAPATH-15-14815'
|
CSCvy40482
|
9.14MR3: snmpwalk got failed with [Errno 146] Connection refused
error.
|
CSCvy61008
|
Time out of sync between Lina and FXOS
|
CSCvy83116
|
WM standby fails to re-join HA with msg "CD App Sync error
is SSP Config Generation Failure"
|