Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

 

Revision:  Version 9.7(1)24 – 04/18/2018

Files:  asa971-24-smp-k8.bin

Defects resolved since 9.7(1)21:

 

CSCvc71764

Blade got stuck in slave bulk sync after changing the CCL

CSCvd08709

Asymetric path ICMP traffic fails through distributed clustering

CSCvd20408

Threat Defense: Interface capture on ASA CLI causes all traffic to be dropped on data-plane

CSCvg44785

Offloaded flows fail to update their idle timer resulting in connections being incorrectly timed out

CSCvg52545

9300 pair NGFWs in inlineIPS mode do not trigger SNAP packet updates with proper VLAN tags

CSCvg76652

Default DLY value of port-channel sub interface mismatch

CSCvg90403

Blocks of size 80 leak observed when IRB is used in conjunction with multicast traffic

CSCvg97541

Firepower Threat Defense prefilter policy only fast-paths single direction of bidirectional flow

CSCvh23085

Cisco Adaptive Security Appliance Application Layer Protocol Inspection DoS Vulnerabilities

CSCvh95456

Cisco Adaptive Security Appliance Application Layer Protocol Inspection DoS Vulnerabilities

 

 

Revision:  Version 9.7(1)21 – 02/03/2018

Files:  asa971-21-smp-k8.bin

Defects resolved since 9.7(1)16:

 

CSCve61540

Cisco Adaptive Security Appliance Application Layer Protocol Inspection DoS Vulnerabilities

 

CSCvf64643

ERROR on Firepower Threat Defense device: Captive-portal port not available. Try again

 

CSCvf90278

ASA/FTD traceback when enabling or clearing the packet capture buffer

 

CSCvg52995

Unable to save configuration in system context after enabling password encryption in ASA

 

CSCvg58941

Elevated CPU Using Flow-Offload & High Rate of Flow Table Collisions

 

CSCvh79732

Cisco Adaptive Security Appliance Denial of Service Vulnerability

CSCvh81737

Memory leak in Agg-Auth SAML code

CSCvh81870

Memory leak in IKE for aggregate-auth

 

 

Revision:  Version 9.7(1)16 – 11/10/2017

Files:  asa971-16-smp-k8.bin

Defects resolved since 9.7(1)15:

 

CSCto19051

Resolve any vulnerabilities in ASA/FTD lina Heimdal Kerberos code

CSCuj98977

ASA Traceback in thread SSH when ran "show service set conn detail"

CSCvb53233

ASA 9.1(7)9 Traceback with %ASA-1-199010 and %ASA-1-716528 syslog messages

CSCvb97470

asa Rest-api - component monitoring - empty value/blank value

CSCvd00293

VTI - Some sessions do not get cleared from vpn-sessiondb

CSCvd53381

ASA Traceback when saving/viewing the configuration due to time-range ACLs

CSCvd67907

ASA SSL client does not respond to renegotiation request

CSCve06436

Routes do not sync properly between different minor versions during hitless upgrade

CSCve18902

Cisco Adaptive Security Appliance TLS Denial of Service Vulnerability

CSCve34335

Cisco Adaptive Security Appliance TLS Denial of Service Vulnerability

CSCve38446

Cisco Adaptive Security Appliance TLS Denial of Service Vulnerability

CSCve72964

Traceback in DATAPATH-1-2084 ASA 9.(8)1

CSCve73025

All 1700 "4 byte blocks" were depleted after a weekend VPN load test.

CSCve85572

ASA should have a syslog message showing which side closed the connection

CSCve85996

Deployment timeouts after 30 minutes due to expand of ACE during deployment

CSCve97874

ASA: Low free  DMA Memory on versions  9.6 and later

CSCvf17214

ASA Exports ECDSA as corrupted PKCS12

CSCvf25666

An ASA with low free memory fails to join existing cluster and could traceback and reload

CSCvf28749

ASA not sending register stop when mroute is configured

CSCvf31539

ASA Connections stuck in idle state with DCD enabled

CSCvf34791

Install 6.2.2-1290 sfr on a ASA with firepower -  asa cores

CSCvf37947

ASA creates a BVi0 interface on a custom routed context

CSCvf43650

OSPF route not getting installed on peer devices when an ASA failover happens with NSF enabled

CSCvf44142

ASA 9.x: DNS inspection appending "0" on PTR query

CSCvf54081

TLS version 1.1 connection failed no shared signature algorithms@t1_lib.c:3106

CSCvf54981

ASA - 80 Byte memory block depletion

CSCvf56506

ASA 9.6(2), 9.6(3) traceback in DataPath

CSCvf56917

ASA doesn't send LACP PDU during port flap in port-channel

CSCvf57908

Transparent Firewall: Ethertype ACLs installed with incorrect DSAP value

CSCvf61419

Traceback in thread DATAPATH due to NAT

CSCvf63108

ASA drops the IGMP Report packet which has Source IP address 0.0.0.0

CSCvf63718

Cisco Adaptive Security Appliance Flow Creation Denial of Service Vulnerability

CSCvf72930

FTD may traceback in Thread Name appAgent_monitor_nd_thread during device registration

CSCvf74218

ASAv image in AWS GovCloud not working in Hourly Billing Mode

CSCvf76281

IKEv2 RA cert auth. Unable to allocate new session. Max sessions reached

CSCvf79262

OpenSSL CVE-2017-3735 "incorrect text display of the certificate"

CSCvf81222

Memory leak in 112 byte bin when packet hits PBR and connection is built

CSCvf81932

'Incomplete command' error with some inspects due to K7 license

CSCvf83709

Slave kicked out due to CCL link failure and rejoins, but loses v3 user in multiple context mode

CSCvf85065

ASA: Traceback by Thread Name idfw_proc

CSCvf87899

ASA - rare scheduler corruption causes console lock

CSCvf94973

ASA on FP 2100 traceback when uploading AnyConnect image via ASDM

CSCvg01132

ASA : After upgrading from 9.2(4) to 9.2(4)18 serial connection hangs

CSCvg09778

ASA-SSP HA reload in CP Processing due to DNS inspect

CSCvg17478

traceback with Show OSPF Database Commands

CSCvg25694

Assert Traceback, thread name : cli_xml_server

CSCvg35618

Cisco Adaptive Security Appliance Remote Code Execution and Denial of Service Vulnerability

 

 

Revision:  Version 9.7(1)15 – 09/05/2017

Files:  asa971-15-smp-k8.bin

Defects resolved since 9.7(1)8:

 

CSCuj69650

ASA block new conns with "logging permit-hostdown" & TCP syslog is down

CSCuv63875

ASA traceback in Thread Name:ci/console while running show ospf commands

CSCuw37752

FTP data conn scaling fails with dynamic PAT

CSCuy48364

ASA 'show memory' output may not properly report total available memory in 9.5(2) and later

CSCuz52474

Evaluation of pix-asa for OpenSSL May 2016

CSCuz72137

ASA dropping packets with "novalid adjacency" though valid ARP entry avail

CSCuz77293

OSPF multicast filter rules missing in cluster slave

CSCva92997

9.7.1 traceback in snp_fp_qos

CSCvb40875

Default inspect statements are missing on ASA 5500-x and 2100 device running Threat Defense

CSCvb44254

ASA 5506-X Firepower Threat Defense Reset Button

CSCvb75685

EZVPN NEM client can't reconnect after "no vpnclient enable" is entered

CSCvb91810

ASA - Incorrect interface-based route-lookup if more specific route exist out different interface

CSCvc18200

print the thread name for non-crashing threads in crash info

CSCvc56526

CEP records edit page take minutes to load

CSCvc56919

Traffic drops for reverse UDP/TCP IPv6 traffic over IPv4 tunnel

CSCvc82270

ASA 1550 block gradual depletion

CSCvc83462

gzip compression not working via Webvpn

CSCvc85369

ASA does not respond to IPv6 MLD Query.

CSCvc96614

ASA: IKEv2 ipsec-proposal command removed if more than 9 proposals configured in single command

CSCvd01130

ASA TCP SIP inspection translation not working when IP phone is behind VPN tunnel

CSCvd03343

Unable to configure SSH public key auth for non-system contexts

CSCvd26699

ASA erroneously triggers syslog ID 201011

CSCvd35811

Traceback in thread name DATAPATH

CSCvd41423

CRL must be signed by certificate containing cRLSign key usage

CSCvd49262

Traceback when trying to save/view access-list with giant object groups (display_hole_og)

CSCvd49550

ASA with 9.5.1 and above does not show SXP socket when managment0/0 is used as src-ip

CSCvd50107

ASA traceback in Thread name: idfw_proc on running "show access-list", while displaying remark

CSCvd50389

RT#687120: Bookmark Issue with clientless VPN - SAML

CSCvd55115

ASA in cluster results in incorrect user group mappings between the Master and Slave

CSCvd55999

%ASA-3-216001: internal error in ci_cons_shell: thread data misuse

CSCvd58094

ASA traceback in ARP thread, PBR configured

CSCvd58321

Web folder filebrowser applet code signing certificate expired

CSCvd58417

DCERPC inspection drops packets and breaks communication

CSCvd61308

ASA backup in multicontext fails due to [Running Configurations] ERROR

CSCvd66303

Error deploying ASAv on ESXi vCenter 6.5

CSCvd68518

Traceback in Thread Name: Unicorn Admin Handler

CSCvd71473

ASA: slow memory leak when using many DNS queries

CSCvd76939

ASA policy-map configuration is not replicated to cluster slave

CSCvd77893

ASA may generate an assert traceback while modifying access-group

CSCvd79797

ASA local dns resolution fails when dns server is reachable through a site to site ipsec tunnel

CSCvd79863

FTD OSPF with ECMP, packets are sent to peer in down state for existing connections

CSCvd80740

FTD-VPN: VPN RRI not getting synced between Master and Slave units

CSCvd82064

Cisco Adaptive Security Appliance Authenticated Cross-Site Scripting Vulnerability

CSCvd82265

Increase memory allocated to rest-agent on ASAv5

CSCvd87211

ASA traceback when trying to remove configured capture

CSCvd87647

ASA traceback in Thread Name: fover_parse performing upgrade from 9.1.5 to 9.4.3

CSCvd89003

ASA traceback observed in Datapath due to SIP inspection

CSCvd89925

Unable to switch standby unit of the failover pair to active

CSCvd90071

Allow ASAv5 to operate using > 1GB memory

CSCvd90079

ASAv5: Reduce DMA packet memory to 64MB

CSCvd90096

WebVPN forces IE to use IE8 mode

CSCvd92423

ASA Traceback in Unicorn Proxy Thread

CSCvd97249

Firepower Threat Defense: block depletion with continuous SSL traffic and decrypt resign enabled.

CSCvd97568

FTD traceback observed during failover synchronization.

CSCvd99476

The interactive icons on internal bookmark site not showing properly (+CSCO+0undefined)

CSCvd99859

ASA may drop DNS reply containing only additional RR of type TXT

CSCvd99945

ASA traceback when customer was authenticating to AnyConnect

CSCve02469

ASA Issue with bgp route summarization(auto-summary)and route advertisement

CSCve02854

SFR Backplane is pulling the public address for policy match instead of ASA inside address

CSCve03387

Proxy ARP information for SSH NLP NAT is not updating on the FTD upon failover

CSCve03974

ASA with FirePOWER services module generates traceback and reload

CSCve04326

Slave should have use CCL to forward traffic instead of blackholing when egress interface is down

CSCve04443

ASAv Azure: Allow 750 VPN sessions on ASAv30

CSCve05841

ASA reloaded while joining cluster and active as slave

CSCve06367

Show Crypto Acclerator shows status as booting for hardware devices

CSCve07856

CRL verification fails due to incorrect KU after CSCvd41423

CSCve08664

Dist-S2S: tunnels stay up even after passing vpn idle timeout in Multimode

CSCve08898

Memory leak with capture with trace and clear capture

CSCve08947

In multi-context ASA drops traffic sourced from certain ports when interface PAT is used

CSCve09249

ASA: Active FTP not working with extended keyword in NAT.

CSCve12654

ASA clustering to support rollback feature with CSM

CSCve13410

Upgrading the ASA results in No Valid adjacency due to track configure on the route

CSCve14758

Standby ASA not learning routes via RIP

CSCve15873

ASA: Multicast packets getting dropped starting code 9.6.3

CSCve18293

ASA traceback observed in datapath

CSCve18880

Username is not fetched from certificate when certificate map is used in clientless portal

CSCve19179

Cisco Adaptive Security Appliance WebVPN Cross-Site Scripting Vulnerability

CSCve19683

FP4100 SSP 9.6.2 / cluster - Tx queue stuck causing traffic drop to occur

CSCve20346

ASA SNI connection fails after upgrade - no shared cipher

CSCve20438

activate-tunnel-group-scripts not available in 9.6.3.1

CSCve21824

hostscan data-limit service-internal command must be exposed and documented

CSCve23033

ICMP Unreachables (PMTU) dropped indicating "Routing failed to locate next hop"

CSCve23091

Auto-RP packet is dropped due to no-route - No route to host

CSCve23784

ASA may traceback on displaying access-list config or saving running config

CSCve24088

Smart Licensing ID cert renewal failure should not deregister product instance

CSCve24299

Traceback in Thread Name: IP RIB Update when routes are redistributed

CSCve28027

Calls not working with CUCI Lync version 11.6.3 on ASA

CSCve29989

ASA - Traceback in DATAPATH during PAT pool socket allocation

CSCve31809

ASA corrupt dst mac address of return traffic from l2tp client

CSCve31880

network_udpmod_get not releasing shr_lock in rare error case

CSCve34729

ASA interfaces may stop passing traffic after ASA reload with FIPS mode enabled

CSCve37948

ASA does not install routes learned via OSPF over IPSec using UDP/4500

CSCve42460

NSF IETF/CISCO commands getting removed on reload

CSCve42583

ASA: IPv6 protocol X rule for passing through FW is dropping packets with Invalid IP length message

CSCve43146

AnyConnect new customization creation fails on ASDM for all ASA versions above 9.5(3)

CSCve44561

ASA sends the ICMP unreachable type 3 code 4 in the wrong direction when SFR redirection enabled

CSCve46883

FTD Diagnostic Interface does Proxy ARP for br1 management subnet

CSCve47393

OSPF Rogue LSA with maximum sequence number vulnerability

CSCve48105

Slave reports Master's interface status as "init" while it is up

CSCve50118

ASA Memory Leak - RSA toolkit

CSCve53582

SSH Connections to ASA fail with SLA monitoring & nonzero floating-conn timeout

CSCve57150

vpn vlan mapping issue

CSCve57548

ASA- Traceback in 'Thread Name : Datapath' on crypto_SSL functions

CSCve58709

ASA 9.5.1 onwards, Traffic incorrectly routed instead of management interface

CSCve60829

ASA Cluster : Potential UDP loop on cluster link with PAT pool

CSCve61284

ASA Log message 414003 may be generated with bogus IP data when TCP Syslog Server down

CSCve63762

ASASM: Interface vlans going to admin down after reload.

CSCve71661

FTD - Multicast and BPDU traffic dropped due to dst-l2_lookup-fail

CSCve72155

Memory leak at location "snp_fp_encrypt" when syslog server is reachable over the VPN tunnel

CSCve72227

IPsec SA fail to come up and flap with more than 1000 IPsec SA count in ASA5506/5508/5516

CSCve73556

ASA traceback on websns_rcv_tcp

CSCve77440

Traceback in Unicorn Proxy Thread due to Webvpn

CSCve78986

ASA/ 9.6.3 // WebVPN Smart tunnel works but floods windows with event viewer

CSCve90305

Contexts are missing on ASA once Chassis reloads after becoming Master on 9.7 and later code

CSCve91068

Cisco Adaptive Security Appliance HREF Cross Site Scripting Vulnerability

CSCve94886

Traceback on ASA with Firepower Services during NAT rule changes and packet capture enabled

CSCve95969

Unable to scale the flash virtualisation feature up to 250 contexts

CSCve97831

CDA agent stucks in 'Probing' when domain-lookup is enable

CSCve99752

Edit Second password on ASDM AC downloads but ignores the change ASA 9.8.1 higher

CSCvf01873

Regex is not matching for HTTP argument field

CSCvf07075

ASA - Crypto accelerator traceback in a loop

CSCvf11695

Duplicate host entries in flow-export action cause traceback after policy deployment

CSCvf14391

multicast traffic sourced from anyconnect pool dropped due to reverse path checked.

CSCvf16142

ASA-5-720012:(VPN-Secondary)Failed to update IPSec failover runtime data in ASA cluster environment

CSCvf16429

Ikev2 Remote Access client sessions stuck in Delete state

CSCvf19938

ASAv: Upgrade issues to the 9.7.1.4 and 9.8.1 when installed on Hyper-V Windows Server 2012-R2

CSCvf22930

FP9300 9.7.1.10 FTD HA  traceback in Datapath

CSCvf24063

ASA5585 traceback in DATAPATH - snp_vpn_process_natt_pkt

CSCvf24387

EC Certificates that are imported to the ASA in PKCS12s cannot be used for SSL

CSCvf38655

ASA traceback in fover_parse after version up

CSCvf41547

traceback in watchdog process

CSCvf44950

iOS and OS X IKEv2 Native Clients unable to connect to ASA with EAP-TLS

 

 

Revision:  Version 9.7(1)8 – 04/27/2017

Files:  asa971-8-smp-k8.bin

Defects resolved since 9.7(1)4:

 

CSCuj69650

ASA block new conns with "logging permit-hostdown" & TCP syslog is down

CSCut09459

incorrect failover status for contexts via SNMP

CSCvb28491

Unable to run show counters protocol ip

CSCvb92548

ASA matches incorrect ACL with object-group-search enabled

CSCvc07112

Implement detection and auto-fix capability for scheduler corruption problems

CSCvc11628

Pre-fill feature extracts username from wrong cert (cert 1-machine) for double cert vs.(cert 2-user)

CSCvc24380

Traceback on thread name IKE Daemon at mqc_enable_qos_for_tunnel

CSCvc46502

FTD Cluster 9K block depletion with fragmented Traffic

CSCvc55674

ASA: IPSec SA failed to come up

CSCvc61818

CTP after failed attempt sends the domain along with the username

CSCvc61845

RDP plugin activex Full Screen option is not available with ASA 9.6.2 version

CSCvc27704

Logs lost when TCP is used as transport protocol for Syslogs

CSCvc85369

ASA does not respond to IPv6 MLD Query.

CSCvc86554

Traceback with ASA 9.5(2)11 on active unit during DNS inspection

CSCvc87914

ASA traceback and Reload on Config Sync Failure

CSCvc91839

Unable to deploy policy on FTD devices due to wrong XML parsing

CSCvc92982

Unable to delete Configured Auto NAT from FMC

CSCvc93947

ASA(9.1.7.12):Connection entries created for multicast streams through standby ASA.

CSCvc97734

Deployment fails when management-only enabled on port-channel interface

CSCvd01736

L2TP connects only sometimes when DHCP used

CSCvd03261

ASAv Goes Unresponsive / VPN fails to function after restart

CSCvd06527

SNMPv3 linkup/linkdown should be generated through admin context

CSCvd08200

Slow Memory leak in ASA

CSCvd14266

ASA traceback in DATAPATH-41-16976 thread

CSCvd15843

Port Forwarding Session times out due to "vpn-idle-timeout" in group-policy while passing data

CSCvd18126

ASA traceback in thread name DATAPATH

CSCvd21154

5585 does not unbundle its data intfs for 30 seconds after leaving cluste

CSCvd21541

Cannot delete port-object once created under the Service object group in ASA 944

CSCvd21665

ASA w/ RRI and OSPF : Fails to flush route from ASP routing table

CSCvd23016

ASA may traceback when copying capture out using tftp

CSCvd23471

ASA may traceback while loading a large context config during bootup

CSCvd24066

ASA drops web traffic when IM inspection is enabled.

CSCvd26939

SNMP lists same Hostname for all FTD managed devices

CSCvd28859

ASA: PBR Memory leak for ICMP traffic

CSCvd29150

Mgmt route deletion removes data plane route too.

CSCvd33044

FTD traceback at "cli_xmlserver_thread" while deploying access-control policy

CSCvd33787

Assertion in syslog.c due to uauth

CSCvd39113

Cluster C-Hash table is updated with one more unit despite the new unit didn't join the setup

CSCvd41052

Scheduler Queue Corruption leads to connectivity failures or failover problems after 9.6(2)

CSCvd41423

CRL must be signed by certificate containing cRLSign key usage

CSCvd43309

Access-lists not being matched for a newly created object-group

CSCvd46633

timeout conn-holddown shows incorrect syntax help

CSCvd47781

ASA traceback while doing in-service upgrade

CSCvd53884

Firepower (SFR) module data plane down after reload of module

CSCvd55983

Traceback in Thread Name: dhcp_daemon

CSCvd56292

Default "global_policy" service-policy removed after reboot

CSCvd59063

Cisco Adaptive Security Appliance Authentication Denial of Service Vulnerability

CSCvd62509

ASA traceback in Thread Name: accept/http when ASDM is displaying "Access Rules"

CSCvd63718

ASA-FP9300 traceback in thread name IPSEC MESSAGE HANDLER

CSCvd64416

ASA All contexts use the same EIGRP router-ID upon a reload

CSCvd64693

EIGRP routes wrongly being advertising on mgmt routing table vrf after disabling and enabling EIGRP

CSCvd65797

ASA may traceback when changing a NAT related object to fqdn

CSCvd69804

ASA - Interface status change c

 

 

Revision:  Version 9.7(1)4 – 04/04/2017

Files:  asa971-4-smp-k8.bin

Defects resolved since 9.7(1)2:

 

CSCvc96586

9K Blocks counters has issues which stops the traffic punted to snort, stating snort busy

CSCvd78303

ARP functions fail after 213 days of uptime, drop with error 'punt-rate-limit-exceeded'

 

 

Revision:  Version 9.7(1)2 – 02/28/2017

Files:  asa971-2-smp-k8.bin

Defects resolved since 9.7(1):

 

CSCuv61791

CWS redirection on ASA may corrupt sequence numbers with https traffic

CSCuw88759

ASA: Protocol and Status showing UP without connecting the interface

CSCvc00689

ASA : memory leak due to ikev2

CSCvc25281

Error synchronizing the SNMPv3 user after rebooting a cluster unit

CSCvc37557

SSL connection hangs between ASA and backend server in clientless WebVPN

CSCvc38425

ASA with FirePOWER module generates traceback and reloads

CSCvc48640

ASA not update access-list dynamically when forward-reference enable is configured

CSCvc52072

Webvpn portal not displayed corrrectly for connections landing on default webvpn group.

CSCvc52272

ASA inspection-MPF ACL changes are not getting ordered correctly in the ASP Table

CSCvc52879

Reloading Active unit in Active/Standby ASA failover pair is not triggering a failover.

CSCvc58272

ASA incorrectly processing negative numbers in wrappers, resulting in graphical webvpn issue

CSCvc60254

SIP: 200 OK messages with multiple seqments not reassembled correctly

CSCvc60964

ASA L3 Cluster: DHCP relay drops DHCPOFFER in case of asymmetric routing

CSCvc62252

Tracking route is up while the reachability is down

CSCvc62556

Traceback in ASA Cluster Thread Name: qos_metric_daemon

CSCvc65409

Traceback observed on gtpv2_process_msg on cluster

CSCvc77123

ASA may traceback in network_tcpmod_close_conn with AnyConnect IPv6 DTLS stress scenario

CSCvc79077

ASA watchdog traceback during cluster config sync with rest-api enabled

CSCvc79371

ASA nat pool not getting updated correctly.

CSCvc79454

Unable to configure ssh public auth for script users

CSCvc82146

ASA traceback in threadname Datapath

CSCvc88411

1550-byte block depletion seen due to Radius Accounting packets

CSCut07712

ASA - TO the box traffic break due to int. missing in asp table routing

CSCum28756

ASA: Auth failures for SNMPv3 polling after unit rejoins cluster

CSCuv86562

ASA traceback in thread name fover_health_monitoring_thread