Version 6.7.0.3 Resolved Issues
Bug ID |
Headline |
---|---|
AWS FTD: Deployment failure with ERROR: failed to set interface to promiscuous mode |
|
FXOS: some interface transition logs have no reason |
|
SPLIT-BRAIN: Pre allocation of blocks for failover control messages |
|
snmpd is respawning frequently on fxos for FP21xx device |
|
FMC System processes are starting |
|
TD2 does not load balance MPLS across backplane interfaces and sends it all to first interface |
|
Firepower may reboot for no apparent reason |
|
cfprApSmMonitorTable is missing in the FP2K MIB |
|
FTD 2100 - SNMP: incorrect values returned for Ethernet statistics polling |
|
MsgLayer[PID]: Error : Msglyr::ZMQWrapper::registerSender() : Failed to bind ZeroMQ Socket |
|
CIAM: net-snmp 5.1 CVE-2019-20892 |
|
Unable to select multiple devices for scheduled backups |
|
Policy Deployment Failure on FMC due to ERROR in SnortAttribConfig |
|
Static routes deleted from the FMC without user deleting it. |
|
FTD does not try all the crl urls for getting crl file |
|
Fastpath rules for Firepower 8000 series stack disappear randomly from the FMC |
|
No router BGP pushed after making chnages on 9300 intra chassis cluster |
|
Syncd process hangs due to SLA |
|
System might hit previously missing memcap limits on upgrade to version 6.6.0 |
|
Message appearing constantly on diagnostic-cli |
|
KP fxos snmp has uninit strings for entPhysicalSerialNum,entPhysicalAssetID on EPM index |
|
4100/9300: Cannot associate port channel / interface to App |
|
FMC upgrade failure to 6.6.0, 6.6.1, 6.6.3, or 6.7.0 at 800_post/1027_ldap_external_auth_fix.pl |
|
Cisco ASA Software and FTD Software SNMP Access Vulnerability |
|
Traffic from VTI interface hitting wrong rule |
|
"Link not connected" error when using WSP-Q40GLR4L transceiver and Arista switch with Firepower 4100 |
|
SSH access with public key authentication fails after FXOS upgrade |
|
ASA upgrade failed with: "CSP directory does not exist - STOP_FAILED Application_Not_Found" |
|
Failed event for standby received on Active causes future deployments to be skipped on standby |
|
CIAM: linux-kernel 3.14.39 CVE-2020-14305 and others |
|
Syslog-ng not starting up while CC mode due to possble bad syslog-ng patch |
|
Radius Key with the ASCII character " configured on FXOS does not work after chassis reload. |
|
FXOS upgrade does not do proper compatibility check for FTD image |
|
FTD running multi-instance mode gets snort GID 3 rules disabled after SRU install and deploy |
|
ENH: Rename status BYPASS-FAIL for fail-to-wire inline pairs |
|
FTD-API: LDAP Attribute map not handling ldapValue including a space |
|
CIAM: curl 7.66.0 CVE-2020-8286 and others |
|
URL is not updated in the access policy URL filtering rule |
|
FP2100 ASA - 1 Gbps SFP in network module down/down after upgrade to 9.15.1.1 |
|
WR6, WR8 and LTS18 commit id update in CCM layer (sprint 101, seq 4) |
|
Firepower 2100: ASA/FTD generates message "Local disk 2 missing on server 1/1" |
|
FXOS upgrade fails with error "does not support application instances of deployment type container" |
|
SFDataCorrelator exits after FTD upgrade to 6.7 caused by ClamAV |
|
Need handling of rmu read failure to ignore link state update when link state API read fails |
|
FXOS reporting old FTD version after FTD upgrade to 6.7.0 |
|
High snort cpu usage while copying navl attribute |
|
WR6, WR8 and LTS18 commit id update in CCM layer (sprint 103, seq 5) |
|
Firepower memory leak in svc_sam_dcosAG |
|
FXOS clock sync issue during blade boot up due to "MIO DID NOT RESPOND TO FORCED TIME SYNC" |
|
FDM: Need to update various items to use STO Certificate Trust Bundle (QuoVadis Root CA Issue) |
|
Deployment gets failed for snmp settings while deleting snmpv1 and adding snmpv3 at a time in 6.6.3 |
|
Evaluate the impact of NGFW for CVE-2021-1405 |
|
ENH: add a way to disable the FQDN check |
|
CIAM: open-ldap 2.4.48 CVE-2020-36230 and others |
|
Update QuoVadis root CA for Smart license as it is getting decommissioned |
|
ma_ctx*.log consuming high diskspace on FPR4100/FPR9300 despite the fix for CSCvx07389 |
|
FTD: SNMP host configured with diagnostic int able to poll management int |
|
Cisco Firepower Management Center Open Redirect Vulnerability |
|
Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation |
|
FXOS show fault warning code F4526902 |
|
ASA/FTD Watchdog forced traceback and reload in Threadname: vnet-proxy (rip: socks_proxy_datarelay) |
|
WR6, WR8 and LTS18 commit id update in CCM layer(sprint 105, seq 6) |
|
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and |
|
Cisco ASA Software and FTD Software Identity-Based Rule Bypass Vulnerability |
|
CIAM: openssl 1.1.1g |
|
Snort process may traceback and restart due TLS1.3 flow |
|
ASA CP CPU wrong calculation leads to high percentage (100% CP CPU) |
|
Update SSEConnector config to use the CA bundle /etc/ssl/certs.pem |
|
Cisco Firepower Management Center Cross-site Scripting Vulnerability |
|
FTD Hotfix Cisco_FTD_SSP_FP2K_Hotfix_O installation fails on script 000_start/125_verify_bundle.sh |
|
Handle CIMC Watchdog reset in MIO |
|
WR6, WR8 and LTS18 commit id update in CCM layer(sprint 107, seq 7) |
|
FMC RAVPN: Deployment is failing when IPv6 DNS is configured under Group Policy |
|
access list is not working on 6.7 |
|
Cisco ASA and FTD Software Resource Exhaustion Denial of Service Vulnerability |
|
Slow file transfer or file upload with SSL policy is applied with Decrypt resign action |
|
Evaluation of ssp for OpenSSL March 2021 vulnerabilities |
|
FMC upgrade failure to 6.6.3 on 999_finish/935_change_reconciliation_baseline.pl |
|
Cisco Firepower Threat Defense Software Command Injection Vulnerabilities |
|
Not able to set Bangkok time zone in FPR 2110 |
|
Supportive change in ASA to differentiate, new ASDM connections from existing ASDM context switch |
|
ASAv Azure: Some or all interfaces might stop passing traffic after a certain period of run time |
|
FTD-API: ruleId duplicate sequence number causes invalid snort ngfw.rules to be deployed |
|
WR6, WR8 and LTS18 commit id update in CCM layer(sprint 109, seq 9) |
|
Cisco Firepower Threat Defense Ethernet Industrial Protocol Policy Bypass Vulnerabilities |
|
Cisco Firepower System Software Rule Editor Non-impactful Buffer Overflow Vulnerability |
|
Failure accessing FXOS with connect fxos admin from Multi-Context ASA if admin context is changed |
|
FXOS : 'Memory leak' may casue appAG process traceback and reload |
|
WM Standby fails to re-join HA with msg "CD App Sync error is Failed to apply SSP config on standby" |
|
Snort 2.9.16.3-3033 traceback (FTD 6.6.3) |
|
WR6, WR8 and LTS18 commit id update in CCM layer(sprint 110, seq 10) |
|
HA goes to active-active state due to cipher mismatch |
|
Syncd exits repeatedly on secondary FMC part of FMC HA |
|
FTD 2110 ascii characters are disallowed in LDAP password |
|
FDM - GUI Inaccessible - tomcat is opening too many file descriptors |
|
Cisco Firepower Threat Defense Software SSH Connections Denial of Service Vulnerability |
|
Cisco Firepower Threat Defense Software Command Injection Vulnerabilities |
|
Cisco Firepower Threat Defense Command Injection Vulnerability |
|
Web portal persistent redirects when certificate authentication is used. |
|
Cisco Firepower Threat Defense Command Injection Vulnerability |
|
Cisco ASA and FTD Software Web Services Interface Cross-Site Scripting Vulnerability |
|
FTD unnecessarily ACKing TCP flows on inline-pair deployment |
|
FPR1K: Fiber SFP Interfaces down due to speed autonegotiation disabled |
|
QP FTD application fails to start due to outdated affinity.conf following FXOS/FTD upgrade |
|
When ASA upgrade fails, version status is desynched between platform and application |
|
WR6, WR8 and LTS18 commit id update in CCM layer(sprint 111, seq 11) |
|
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DoS |
|
Lina traceback and core file size is beyond 40G and compression fails. |
|
9.14MR3: snmpwalk got failed with [Errno 146] Connection refused error. |
|
Cisco Firepower Threat Defense Software CLI Arbitrary File Write Vulnerability |
|
Cisco Firepower Management Center Software Authenticated Directory Traversal Vulnerability |
|
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DoS |
|
Firepower flow-offload stops offloading all existing and new flows |
|
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DoS |
|
Denial of Service vulnerability handling the config-request request |
|
Time out of sync between Lina and FXOS |
|
WR6 and WR8 commit id update in CCM layer(sprint 113, seq 12) |
|
AppAgent Heartbeat enhancement |
|
FPR4100/9300 IPv6 config cannot be applied using Rest API LTP on 9300/4100 Supervisor |
|
Cisco FMC Software Configuration Information Disclosure Vulnerability |
|
High snort cpu usage while copying navl attribute - ( Fragmented metadata ) |
|
Cisco FMC Software Configuration Information Disclosure Vulnerability |
|
FMC should not allow to configure port-channel ID higher than 8 on FPR1010 |
|
Include the ios pem files into the patch upgrade package for vFTD |
|
FTD 1000 standby fails to re-join HA with msg "CD App Sync error is SSP Config Generation Failure" |
|
FXOS process core pruned/deleted from system files (no validation) |
|
Cisco ASA and FTD Web Services Denial of Service Vulnerability |
|
s2sCryptoMap Configuration Loss |
|
Cisco ASA and FTD Software IKEv2 Site-to-Site VPN Denial of Service Vulnerability |
|
Incorrect Access rule matching because of ac rule entry missing |
|
Roll back changes introduced by CSCvr33428 and CSCvy39659 |
|
Resolve spurious status actions checking speed values twice in FXOS portmgr |
|
FP-1010 HA link goes down or New hosts unable to connect to the device |
|
No connection events due to SFDataCor process stuck |
|
In Firepower 1010 device, after upgrading ASA app, device going for fail safe mode |
|
Multiple Cisco Products Snort Modbus Denial of Service Vulnerability |
|
FTD Deployment error when FMC pushes PFS21 and IKEv1 settings on same crypto map entry |
|
Deleted files holding disk space under Java process |
|
Random packet block by Snort in SSL flow |
|
IPReputation Feed Error Message-Method Not Allowed |
|
Security: CVE-2021-44228 -> Log4j 2 Vulnerability |
|
Expired certs cause Security Intel. and malware file preclassification signature updates to fail |
|
6.7.0.3:Peer certificate cannot be authenticated with known CA certificates upon doing SRU update |
|
Unable to register FMC with the Smart Portal |