Cisco ASA Interim Release Notes

 

The software images listed below are Interim releases.  They contain bug fixes which address specific issues found since the last Feature or Maintenance release.  The images are fully supported by Cisco TAC and will remain on the download site only until the next Maintenance release is available. If you do not have a specific problem which is resolved by an Interim release, we recommend that you use the Feature or Maintenance release images.

 

Important:  These images were not fully regression tested.  Each individual fix was unit tested, and the image has had a limited amount of automated regression testing to confirm a baseline of functionality.  Keep this testing status in mind if you decide to run them in a production environment.  We strongly encourage you to upgrade to a fully tested Maintenance or Feature release when it becomes available.

 

Revision:  Version 9.16(2)14 – 2/23/2022

Files:  asa9-16-2-14-smp-k8.bin, cisco-asa-fp1k.9.16.2.14.SPA, cisco-asa-fp2k.9.16.2.14.SPA, cisco-asa.9.16.2.14.SPA.csp

Defects resolved since 9.16(2)13:

 

CSCvx97053

Unable to configure ipv6 address/prefix to same interface and network in different context

CSCvy04430

Management Sessions fail to connect after several weeks

CSCvy55439

FTDv throughput degredation due to frequent PDTS read/write

CSCvy60831

ASA/FTD Memory block location not updating for fragmented packets in data-path

CSCvz05541

ASA55XX: Expansion module interfaces not coming up after a software upgrade

CSCvz58376

Snort down after deploying the policy

CSCvz68336

SSL decryption not working due to single connection on multiple in-line pairs

CSCvz76966

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DNS DoS

CSCvz95949

FP1120 9.14.3 : temporary split brain happened after active device reboot

CSCwa02929

FTD Blocks Traffic with SSL Flow Error CORRUPT_MESSAGE

CSCwa28822

FTD moving UI management from FDM to FMC causes traffic to fail

CSCwa30114

Error:NAT unable to reserve ports when using a range of ports in an object service

CSCwa33898

Cisco Adaptive Security Appliance Software Clientless SSL VPN Heap Overflow Vulnerability

CSCwa34287

ASA: Loss of NTP sync following a reload after upgrade

CSCwa38277

ASA NAT66 with big range as a pool don't works with IPv6

CSCwa42594

ASA: IP Header check validation failure when GTP Header have SEQ and EXT field

CSCwa53489

Lina Traceback and Reload Due to invalid memory access while accessing Hash Table

CSCwa57115

New access-list are not taking effect after removing non-existance ACL with objects.

CSCwa58686

ASA/FTD Change in OGS compilation behavior causing boot loop

CSCwa65389

ASA traceback and reload in Unicorn Admin Handler when change interface configuration via ASDM

CSCwa67882

Offloaded GRE tunnels may be silently un-offloaded and punted back to CPU

CSCwa74900

Traceback and reload after enabling debug webvpn cifs 255

CSCwa77073

SNMP is responding to snmpgetbulk with unexpected order of results

CSCwa79980

SNMP get command in FPR does not show interface index.

 

 

Revision:  Version 9.16(2)13 – 1/25/2022

Files:  asa9-16-2-13-smp-k8.bin, cisco-asa-fp1k.9.16.2.13.SPA, cisco-asa-fp2k.9.16.2.13.SPA, cisco-asa.9.16.2.13.SPA.csp

Defects resolved since 9.16(2)11:

 

CSCvy33501

FDM failover pair - new configured sVTI IPSEC SA is not synced to standby. FDM shows HA not in sync

CSCvy40401

L2L VPN session bringup fails when using NULL encryption in ipsec configuration

CSCvz44645

FTD may traceback and reload in Thread Name 'lina'

CSCvz60578

Cluster unit in MASTER_POST_CONFIG state should transition to Disabled state after an interva

CSCvz61658

CPU hogs in update_mem_reference

CSCvz76746

While implementing management tunnel a user can use open connect to bypass anyconnect.

CSCvz81888

NTP will not change to *(synced) status after upgrade to asa-9.15.1/9.16.1.28 from asa-9.14.3

CSCvz86256

Primary ASA should send GARP as soon as split-brain is detected and peer becomes cold standby

CSCvz89126

ASDM session/quota count mismatch in ASA when multiple context switchover is done from ASDM

CSCvz89327

OSPFv2 flow missing cluster centralized "c" flag

CSCvz90375

Low available DMA memory on ASA 9.14 at boot reduces AnyConnect sessions supported

CSCvz91218

Statelink hello messages dropped on Standby unit due to interface ring drops on high rate traffic

CSCvz92016

ASA Privilege Escalation with valid user in AD

CSCvz92932

ASA show tech execution causing spike on CPU and impacting to IKEv2 sessions

CSCvz99222

Clear and show conn for inline-set is not working

CSCwa11052

SNMP Stopped Responding After Upgrading to Version- 9.14(2)15

CSCwa13873

ASA Failover Split Brain caused by delay on state transition after "failover active" command run

CSCwa14485

Cisco Firepower Threat Defense Software Denial of Service Vulnerability

CSCwa14725

ASA/FTD traceback and reload on IKE Daemon Thread

CSCwa15185

ASA/FTD: remove unwanted process call from LUA

CSCwa18858

ASA drops non DNS traffic with reason "label length 164 bytes exceeds protocol limit of 63 bytes"

CSCwa18889

Clock drift observed between Lina and FXOS on multi-instance

CSCwa19443

Flow Offload - Compare state values remains in error state for longer periods

CSCwa19713

Traffic dropped by ASA configured with BVI interfaces due to asp drop type "no-adjacency"

CSCwa36672

ASA on FPR4100 traceback and reload when running captures using ASDM

CSCwa36678

Random FTD traceback during deployment from FMC

CSCwa40719

Traceback: Secondary firewall reloading in Threadname: fover_parse

CSCwa41834

ASA/FTD traceback and reload due to  pix_startup_thread

CSCwa47041

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software DAP DoS

CSCwa55562

Different CG-NAT port-block allocated for same source IP causing per-host PAT port block exhaustion

CSCwa55878

FTD Service Module Failure: False alarm of "ND may have gone down"

 

 

Revision:  Version 9.16(2)11 – 11/30/2021

Files:  asa9-16-2-11-smp-k8.bin, cisco-asa-fp1k.9.16.2.11.SPA, cisco-asa-fp2k.9.16.2.11.SPA, cisco-asa.9.16.2.11.SPA.csp

Defects resolved since 9.16(2)7:

 

CSCvy96325

FTD/ASA: Adding new ACE entries to ACP causes removal and re-add of ACE elements in LINA

CSCvz02398

Crypto archive generated with SE ring timeout on 7.0

CSCvz03524

PKI "OCSP revocation check" failing due to sha256 request instead of sha1

CSCvz20679

FTDv - Lina Traceback and reload

CSCvz33468

[IMS 7.1.0] Nat hitcount not updated in FQDN_NAT

CSCvz40352

ASA traffic dropped by Implicit ACL despite the fact of explicit rules present on Access-list

CSCvz50922

FPR2100: Unable to form L2L VPN tunnels when using ESP-Null encryption

CSCvz55849

FTD Traceback and Reload on process LINA

CSCvz56940

Traceback on MI FTD at boot time

CSCvz66795

ASA traceback and reload in SSH process when executing the command "show access-list"

CSCvz73146

FTD - Traceback in Thread Name: DATAPATH

CSCvz76848

FTD traceback and reload when using DTLS1.2 on RA tunnels

CSCvz85437

FTD 100G interfaces down after upgrade of FXOS and FTD to 2.10.1.159 and 6.6.4

CSCvz89545

SSL VPN performance degraded and significant stability issues after upgrade

CSCvz94153

NTP sync on IPV6 will fail if the IPV4 address is not configured

CSCvz95108

FTD Deployment failure post upgrade due to major version change on device

CSCvz95743

Loss of NTP sync following an upgrade

CSCwa03275

BGP routes shows unresolved and dropping packet with asp-drop reason "No route to host"

CSCwa03347

IPv6 PIM packets are dropped in ASP with invalid-ip-length drop reason

CSCwa04461

Cisco ASA Software and FTD Software Remote Access SSL VPN Denial of Service

CSCwa08262

AnyConnect users with mapped group-policies take attributes from default GP under the tunnel-group

CSCwa15185

ASA/FTD: remove unwanted process call from LUA

 

 

Revision:  Version 9.16(2)7 – 10/27/2021

Files:  asa9-16-2-7-smp-k8.bin, cisco-asa-fp1k.9.16.2.7.SPA, cisco-asa-fp2k.9.16.2.7.SPA, cisco-asa.9.16.2.7.SPA.csp

Defects resolved since 9.16(2)3:

 

CSCvs27336

Traceback on ASA by Smart Call Home process

CSCvu96436

Traceback of master and one slave when a particular lock is contended for long

CSCvx36885

Unit may traceback and reload citing datapath as crashing thread

CSCvx95884

High CPU and massive "no buffer" drops during HA bulk sync and during normal conn sync

CSCvy35737

FTD traceback and reload during anyconnect package verification

CSCvy57905

VTI tunnel interface stays down post reload on KP/WM platform in HA

CSCvy90836

ASA Traceback and reload in Thread Name: SNMP ContextThread

CSCvy91668

PAT pool exhaustion with stickiness traffic could lead to new connection drop.

CSCvy98458

FP21xx -traceback "Panic:DATAPATH-10-xxxx -remove_mem_from_head: Error - found a bad header"

CSCvz00032

FTD tracebacks and reloads on Thread name Lina

CSCvz20679

FTDv - Lina Traceback and reload

CSCvz37306

ASDM session is not served for new user after doing multiple context switches in existing user

CSCvz38332

FTD/ASA - Stuck in boot loop after upgrade from 9.14.2.15 to 9.14.3

CSCvz38692

ASAv traceback in snmp_master_callback_thread and reload

CSCvz39646

ASA/AnyConnect - Stale RADIUS sessions

CSCvz43414

Internal ldap attribute mappings fail after HA failover

CSCvz43455

ASAv observed traceback while upgrading hostscan

CSCvz48407

Traceback and reload in Thread Name: DATAPATH-15-18621

CSCvz50712

TLS server discovery uses incorrect source IP address for probes in AnyConnect deployment

CSCvz53142

ASA does not use the interface specified in the name-server command to reach IPv6 DNS servers

CSCvz55302

FTD/ASA Traceback and reload due to SSL null checks under low memory conditions

CSCvz55395

TCP connections are cleared after configured idle-timeout even though traffic is present

CSCvz57710

conf t is converted to disk0:/t under context-config mode

CSCvz58710

ASA traceback due to SCTP traffic.

CSCvz61160

ASA traceback on DATAPATH when handling ICMP error message

CSCvz62379

Cisco ASA and FTD Software Dynamic Access Policies Denial of Service Vulnerability

CSCvz64470

Unexpected traceback on the ASA Primary Unit running on 9.8.4.39

CSCvz67003

ASDM session count and quota management's count mismatch. 'Lost connection firewall' msg in ASDM

CSCvz69571

ASA log shows wrong value of the transferred data after the anyconnect session terminated.

CSCvz70316

LINA may generate traceback and reload

CSCvz70595

Traceback observed on ASA while handling SAML handler

CSCvz73709

ASA/FTD Standby unit fails to join HA

CSCvz75988

Inconsistent logging timestamp with RFC5424 enabled

CSCvz77744

OSPFv3: FTD Wrong "Forwarding address" added in ospfv3 database

CSCvz84850

ASA/FTD traceback and reload caused by "timer services" function

 

 

Revision:  Version 9.16(2)3 – 09/08/2021

Files:  asa9-16-2-3-smp-k8.bin, cisco-asa-fp1k.9.16.2.3.SPA, cisco-asa-fp2k.9.16.2.3.SPA, cisco-asa.9.16.2.3.SPA.csp

Defects resolved since 9.16(2):

 

CSCvr33428

FMC generates Connection Events from a SYN flood attack

CSCvv43190

Crypto engine errors when GRE header protocol field doesn't match protocol field in inner ip header

CSCvv48942

Snmpwalk showing traffic counter as 0 for failover interface

CSCvx80830

VPN conn fails from same user if Radius server sends a dACL and vpn-simultaneous-logins is set to 1

CSCvx95884

High CPU and massive "no buffer" drops during HA bulk sync and during normal conn sync

CSCvy04343

ASA in PLR mode,"license smart reservation" is failing.

CSCvy21334

Active tries to send CoA update to Standby in case of "No Switchover"

CSCvy32366

After upgrading ASA to 9.15(1)10, ASDM 7.15(1)150 One Time Password (OTP) field does not appear

CSCvy33676

UN-NAT created on FTD once a prior dynamic xlate is created

CSCvy39659

ASA/FTD may traceback and reload in Thread Name 'DATAPATH-15-14815'

CSCvy53461

RSA keys & Certs get removed post reload on WS-SVC-ASA-SM1-K7 with ASA code 9.12.x

CSCvy64911

SNMP MIB value for crasLocalAddress is not showing the IP address

CSCvy74984

ASAv on Azure loses connectivity to Metadata server once default outside route is used

CSCvy96625

Revert 'fix' introduced by CSCvr33428 and CSCvy39659

CSCvz00383

FTD lina traceback and reload in thread Name Checkheaps

CSCvz05189

FTD reload with Lina traceback during xlate replication in Cluster

CSCvz07614

ASA: Orphaned SSH session not allowing us to delete a policy-map from CLI

CSCvz15529

ASA traceback and reload thread name: Datapath

CSCvz20544

ASA/FTD may traceback and reload in loop processing Anyconnect profile

CSCvz21886

Twice nat's un-nat not happening if nat matches a pbr acl that matches a port number instead of IP

CSCvz23157

SNMP agent restarts when show commands are issued

CSCvz29233

ASA: ARP entries from custom context not removed when an interface flap occurs on system context

CSCvz30333

FTD/Lina may traceback when "show capture" command is executed

CSCvz34831

If ASA fails to download DACL it will never stop trying

CSCvz38361

BGP packets dropped for non directly connected neighbors