Cross Platform Release Notes for Cisco IOS Release 15.8(3)M
These release notes support Cisco IOS Release 15.8(3)M and describe new features and related documents.
Cisco IOS Release 15.8(3)M provides the latest innovations for the world’s most demanding networks and is designed to provide a unified network architecture that is stable, reliable, and secure. New features are fully integrated with extensive capabilities already available in Cisco IOS software to provide solutions for enterprise, service provider, and smart grid.
System Requirements
This section describes the system requirements for Cisco IOS Release 15.8(3)M and includes the following sections:
Supported Hardware Platforms
-
Cisco 800 series routers
-
Cisco 900 series routers
-
Cisco 1900 series integrated services routers
-
Cisco Analog Voice Gateways (VG202XM and VG204XM)
-
Cisco Connected Grid Router (CGR) 2000 series (CGR 2010)
-
Cisco Connected Grid Router (CGR) 1000 series (CGR1240,CGR1120)
-
Cisco High Density Analog Voice Gateways (VG350)
-
Cisco Industrial Integrated Services Routers IR8XX (809,829,807)
For more information about the platforms supported in Cisco IOS Release 15.8(3)M, see the “Platform-Specific Information” section on page 9 .
Determining Your Software Version
To determine the version of Cisco IOS software that is currently running on your Cisco network device, log in to the device and enter the show version user EXEC command:
Router> show version
Cisco Internetwork Operating System Software IOS (tm)
15.8 Software (c880data-universalk9-mz.), Version 15.8(3)M, RELEASE SOFTWARE
Upgrading to a new Release
MIBS
Field Notices and Software-Related Tools and Information
Troubleshooting
Upgrading to a New Release
For information about selecting a new Cisco IOS software release, see How to Choose a Cisco IOS Software Release at the following URL:
http://www.cisco.com/en/US/products/sw/iosswrel/ps1834/products_tech_note09186a00800fb9d9.shtml
For information about updating or upgrading Cisco IOS software, see How to Update/Upgrade Cisco IOS Software at the following URL:
Platform-specific documents may also provide information about upgrading to a new software release:
-
Cisco 800 Series Industrial Integrated Services Routers: http://www-author.cisco.com/c/en/us/support/routers/800-series-industrial-routers/products-installation-guides-list.html
-
Cisco 800 series routers:http://www.cisco.com/en/US/products/hw/routers/ps380/prod_installation_guides_list.html
-
Cisco IR 800 series routers: https://www.cisco.com/c/en/us/support/routers/800-series-industrial-routers/products-installation-guides-list.html
-
Cisco 900 Integrated Services Routershttps://www.cisco.com/c/en/us/td/docs/routers/access/900/hardware/installation/guide/b-cisco-ISR900-series-hig.html
-
Cisco 1000 CGR series routers http://www.cisco.com/c/en/us/support/routers/1000-series-connected-grid-routers/products-installation-and-configuration-guides-list.html
-
Cisco 2000 CGR series routers:http://www.cisco.com/en/US/products/ps10977/prod_installation_guides_list.html
-
Cisco 1900 series routers: http://www.cisco.com/en/US/docs/routers/access/1900/hardware/installation/guide/1900_HIG.html
-
Cisco 2900 and 3900 series routers: http://www.cisco.com/en/US/docs/routers/access/2900/hardware/installation/guide/Hardware_Installation_Guide.html
-
Cisco 5900 Embedded Services Routers: http://www.cisco.com/c/en/us/support/routers/5900-series-embedded-services-routers/products-installation-guides-list.html
-
Cisco VG202XM and Cisco VG204XM Voice Gateways: http://www.cisco.com/en/US/docs/routers/access/vg202_vg204/hardware/vg2_vg4hw.html
-
Cisco VG350 Voice Gateway: http://www.cisco.com/en/US/docs/routers/access/vg350/hardware/installation/guide/vg350_hig.html
For instructions on ordering a Cisco IOS upgrade, see the document at the following location: http://www.cisco.com/warp/public/cc/pd/iosw/prodlit/957_pp.html.
To choose a new Cisco IOS software release by comparing feature support or memory requirements, use Cisco Feature Navigator. Cisco Feature Navigator is a web-based tool that enables you to determine which Cisco IOS software images support a specific set of features and which features are supported in a specific Cisco IOS image. You can search by feature or by feature set (software image). Under the release section, you can compare Cisco IOS software releases side by side to display both the features unique to each software release and the features that the releases have in common.
To choose a new Cisco IOS software release based on information about defects that affect that software, use Bug Toolkit at the following URL: http://www.cisco.com/cgi-bin/Support/Bugtool/launch_bugtool.pl.
MIBs
To locate and download MIBs for selected platforms, Cisco IOS releases, and feature sets, use Cisco MIB Locator found at the following URL:
http://tools.cisco.com/ITDIT/MIBS/servlet/index
If Cisco MIB Locator does not support the MIB information that you need, you can also obtain a list of supported MIBs and download MIBs from the Cisco MIBs page at the following URL:
http://www.cisco.com/public/sw-center/netmgmt/cmtk/mibs.shtml
To access Cisco MIB Locator, you must have an account on Cisco.com. If you have forgotten or lost your account information, send a blank e-mail to cco-locksmith@cisco.com. An automatic check will verify that your e-mail address is registered with Cisco.com. If the check is successful, account details with a new random password will be e-mailed to you. Qualified users can establish an account on Cisco.com by following the directions found at this URL:
Field Notices and Software-Related Tools and Information
We recommend that you view the field notices for this release to see if your software or hardware platforms are affected. You can find Field Notices at http://www.cisco.com/en/US/support/tsd_products_field_notice_summary.html.
Visit the Download Software page on Cisco.com to subscribe to Cisco software notifications, locate MIBs, access the Software Advisor, and find other Cisco software-related information and tools. Access the Download Software page at http://www.cisco.com/cisco/software/navigator.html?a=a&i=rpm.
Troubleshooting
The following documents and websites provide assistance with troubleshooting your Cisco hardware and software:
- Troubleshoot and Alerts Product or Technology Selection Page
http://www.cisco.com/cisco/web/psa/troubleshoot.html?mode=prod&level0=268437899
- Cisco 800 Series Routers Troubleshooting Guides
http://www.cisco.com/en/US/products/hw/routers/ps380/prod_troubleshooting_guides_list.html
- Cisco 1240 and 1120 Connected Grid Router Installation Guides
- Cisco 1600 Series Routers Hardware Troubleshooting Index Page
http://www.cisco.com/en/US/products/hw/routers/ps214/products_tech_note09186a008012fb88.shtml
- Troubleshooting Cisco 3900 Series, 2900 Series, and 1900 Series ISRs
http://www.cisco.com/en/US/docs/routers/access/2900/hardware/installation/guide/Trouble.html
- Cisco Unified Communications 500 Series Install and Upgrade Tech Notes
Cisco Error Message Decoder
http://www.cisco.com/pcgi-bin/Support/Errordecoder/index.cgi
- Cisco Support Community
Feature Support
Cisco IOS software is packaged in feature sets that consist of software images that support specific platforms. The feature sets available for a specific platform depend on which Cisco IOS software images are included in a release. Each feature set contains specific Cisco IOS features.
Caution |
Cisco IOS images with strong encryption (including, but not limited to 168-bit [3DES] data encryption feature sets) are subject to U.S. government export controls and have limited distribution. Strong encryption images to be installed outside the United States are likely to require an export license. Customer orders may be denied or subject to delay because of U.S. government regulations. When applicable, the purchaser/user must obtain local import and use authorizations for all encryption strengths. Please contact your sales representative or distributor for more information, or send an e-mail to export@cisco.com. |
Cisco Feature Navigator
Feature-to-image mapping is available through Cisco Feature Navigator. Cisco Feature Navigator is a web-based tool that enables you to determine which Cisco IOS software images support a specific set of features and which features are supported in a specific Cisco IOS image. You can search by feature or by feature set (software image). You can compare Cisco IOS software releases side-by-side to display both the features unique to each software release and the features that the releases have in common.
Cisco Feature Navigator is updated regularly when major Cisco IOS software releases and technology releases occur. For the most current information, go to the Cisco Feature Navigator home page at the following URL:
For help with Cisco Feature Navigator, see the help information at the following URL:
http://www.cisco.com/web/applicat/CFNTOOLS/Help_Docs/help/cfn_support.html
Determining the Software Images (Feature Sets) That Support a Specific Feature
To determine which software images (feature sets) in a Cisco IOS release support a specific feature, go to the Cisco Feature Navigator home page and perform the following steps.
SUMMARY STEPS
- From the Cisco Feature Navigator home page, click Research Features.
- Select your software type or leave the field as “All”.
- To find a feature, you can search by either Feature or Technology (select the appropriate button). If you select Search by Feature, you can further filter your search by using the Filter By text box.
- Choose a feature from the Available Features text box, and click the Add button to add the feature to the Selected Features text box.
- Click Continue when you are finished choosing features.
- In the Release/Platform Tree area, select either your release (from the Train-Release list) or your platform (from the Platform list).
- The “Search Result” table will list all the software images (feature sets) that support the features that you chose.
DETAILED STEPS
Step 1 |
From the Cisco Feature Navigator home page, click Research Features. |
||
Step 2 |
Select your software type or leave the field as “All”. |
||
Step 3 |
To find a feature, you can search by either Feature or Technology (select the appropriate button). If you select Search by Feature, you can further filter your search by using the Filter By text box. |
||
Step 4 |
Choose a feature from the Available Features text box, and click the Add button to add the feature to the Selected Features text box.
Repeat this step to add features. A maximum of 20 features can be chosen for a single search. |
||
Step 5 |
Click Continue when you are finished choosing features. |
||
Step 6 |
In the Release/Platform Tree area, select either your release (from the Train-Release list) or your platform (from the Platform list). |
||
Step 7 |
The “Search Result” table will list all the software images (feature sets) that support the features that you chose.
|
Determining the Features Supported in a Specific Software Image (Feature Set)
To determine which features are supported in a specific software image (feature set), go to the Cisco Feature Navigator home page and perform the following steps.
SUMMARY STEPS
- From the Cisco Feature Navigator home page, click Research Software.
- Select your software type from the drop-down list and chose the Release button in the “Search By” area.
- From the Major Release drop-down list, chose the appropriate major release.
- From the Release drop-down list, choose the appropriate maintenance release.
- From the Platform drop-down list, choose the appropriate hardware platform.
- From the Feature Set drop-down list, choose the appropriate feature set. The Image Details area will provide details on the specific image. The Available Features area will list all the features that are supported by the feature set (software image) that you chose.
DETAILED STEPS
Step 1 |
From the Cisco Feature Navigator home page, click Research Software. |
||
Step 2 |
Select your software type from the drop-down list and chose the Release button in the “Search By” area. |
||
Step 3 |
From the Major Release drop-down list, chose the appropriate major release. |
||
Step 4 |
From the Release drop-down list, choose the appropriate maintenance release. |
||
Step 5 |
From the Platform drop-down list, choose the appropriate hardware platform. |
||
Step 6 |
From the Feature Set drop-down list, choose the appropriate feature set. The Image Details area will provide details on the specific image. The Available Features area will list all the features that are supported by the feature set (software image) that you chose.
|
Memory Recommendations
To determine memory recommendations for software images (feature sets) in your Cisco IOS release, go to the Cisco Feature Navigator home page and perform the following steps.
SUMMARY STEPS
- From the Cisco Feature Navigator home page, click Research Software.
- Select your software type from the drop-down list and choose the Release button in the “Search By” area.
- From the Major Release drop-down list, choose the appropriate major release.
- From the Release drop-down list, choose the appropriate maintenance release.
- From the Platform drop-down list, choose the appropriate hardware platform.
- From the Feature Set drop-down list, choose the appropriate feature set.
- The Image Details area will provide details on the specific image including the DRAM and flash memory recommendations for each image. The Available Features area will list all the features that are supported by the feature set (software image) that you chose.
DETAILED STEPS
Step 1 |
From the Cisco Feature Navigator home page, click Research Software. |
Step 2 |
Select your software type from the drop-down list and choose the Release button in the “Search By” area. |
Step 3 |
From the Major Release drop-down list, choose the appropriate major release. |
Step 4 |
From the Release drop-down list, choose the appropriate maintenance release. |
Step 5 |
From the Platform drop-down list, choose the appropriate hardware platform. |
Step 6 |
From the Feature Set drop-down list, choose the appropriate feature set. |
Step 7 |
The Image Details area will provide details on the specific image including the DRAM and flash memory recommendations for each image. The Available Features area will list all the features that are supported by the feature set (software image) that you chose. |
Features and Important Notes
These release notes describe the following topics:
Important Notes
-
The H.323 functionality is not supported from Cisco IOS 15.7(3)M onwards. This might potentially have an impact on the NAT H.323 ALG functionality. Note that Cisco technical support will not be available for any NAT H.323 ALG issues related to this change. If you are impacted by this change, we recommend that you consider Session Initiation Protocol (SIP) as an alternative solution.
New and Changed Information
This section lists the new hardware and software features supported by Cisco IOS Release 15.3(3)M and contains the following subsections:
New Hardware Features Supported in Cisco IOS Release 15.8(3)M
Cisco 900 Integrated Services Routers
For detailed information, see the following document:
New Software Features Supported in Cisco IOS Release 15.8(3)M
Cisco IR800 Industrial Integrated Services Routers and Cisco 1000 Series Connected Grid Routers Features
For detailed information, see the following Cisco document:
Cisco 900 Integrated Services Routers
For detailed information, see the following document:
https://www.cisco.com/c/en/us/td/docs/routers/access/900/software/configuration/guide/900SCG.html
Bugs for Cisco IOS Release 15.8(3)M
Open and Resolved Bugs
The open and resolved bugs for this release are accessible through the Cisco Bug Search Tool. This web-based tool provides you with access to the Cisco bug tracking system, which maintains information about bugs and vulnerabilities in this product and other Cisco hardware and software products.
Within the Cisco Bug Search Tool, each bug is given a unique identifier (ID) with a pattern of CSCxxNNNNN, where x is any letter (a-z) and N is any number (0-9). The bug IDs are frequently referenced in Cisco documentation, such as Security Advisories, Field Notices and other Cisco support documents. Technical Assistance Center (TAC) engineers or other Cisco staff can also provide you with the ID for a specific bug.
You can save searches that you perform frequently. You can also bookmark the URL for a search and email the URL for those search results.
Note |
If the defect that you have requested cannot be displayed, this may be due to one or more of the following reasons: the defect number does not exist, the defect does not have a customer-visible description yet, or the defect has been marked Cisco Confidential. |
Using the Bug Search Tool
The Cisco Bug Search Tool enables you to filter the bugs so that you only see those in which you are interested. In addition to being able to search for a specific bug ID, or for all bugs in a product and release, you can filter the open and/or resolved bugs by one or more of the following criteria:
- Last modified date
- Status, such as fixed (resolved) or open
- Severity
- Support cases
For more information about how to use the Cisco Bug Search Tool, including how to set email alerts for bugs and to save bugs and searches, see Bug Search Tool Help & FAQ.
Note |
You must have a Cisco.com account to log in and access the Cisco Bug Search Tool. if you do not have one, you can register for an account. |
To use the Cisco Bug Search Tool:
- In your browser, navigate to the Cisco Bug Search Tool.
- If you are redirected to a Log In page, enter your registered Cisco.com username and password and then, click Log In.
- To search for a specific bug, enter the bug ID in the Search For field and press Enter.
- To search for bugs related to a
specific software release, do the following:
- In the Product field, choose Series/Model from the drop-down list and then enter the product name in the text field. If you begin to type the product name, the Cisco Bug Search Tool provides you with a drop-down list of the top ten matches. If you do not see this product listed, continue typing to narrow the search results.
- In the Releases field, enter the release for which you want to see bugs.
The Cisco Bug Search Tool displays a preview of the results of your search below your search criteria. You can mouse over bugs to see more content about a specific bug.
To see more content about a specific bug, you can do the following:
-
Mouse over a bug in the preview to display a pop-up with more information about that bug.
-
Click on the hyperlinked bug headline to open a page with the detailed bug information.
-
To restrict the results of a search, choose from one or more of the following filters:
Filter
Description
Modified Date
A predefined date range, such as last week or last six months.
Status
A specific type of bug, such as open or fixed.
Severity
The bug severity level as defined by Cisco. For definitions of the bug severity levels, see Bug Search Tool Help & FAQ
Rating
The rating assigned to the bug by users of the Cisco Bug Search Tool.
Support Cases
Whether a support case has been opened or not.
Your search results update when you choose a filter.
Resolved Bugs—Cisco IOS Release 15.8(3)M9
Caveat ID Number |
Description |
---|---|
Low flash error when CGR has plenty of space. |
|
Dialer callback cannot trigger on C891. |
|
SNMP OID for SINR giving wrong (static) value of zero. |
|
DHCPv6: Memory allocation of DHCPv6 relay option results in crash. |
|
Backoff algorithm not working as expected with dual stack for reject code 33. |
Open Bugs—Cisco IOS Release 15.8(3)M9
There are no new or open bugs for this release.
Resolved Bugs—Cisco IOS Release 15.8(3)M8
Caveat ID Number |
Description |
---|---|
Interop vrrp does not work between cedge and vedge |
|
Flow Record shows not configured even defined flow monitor |
|
Crash at glbp address comparison |
|
HSRP standby switch unable to reach the VIP |
|
Restart because of bus error |
|
Configure replace crashes device with "Unexpected exception to CPU" |
|
Disabling dot1x command “authentication port-control force-auth” there is no MAC learned |
|
Incorrect temp from MCU causing false over temp alerts |
|
Dialer callback cannot trigger on C891 |
|
'Storm-control shutdown' unexpectedly configured on the interface after "clear counters" |
|
After clearing interface counters, 'hdsl2ShdslEndpointCurrActivationState' returns always 0 |
|
Crash due to DNS server |
Open Bugs—Cisco IOS Release 15.8(3)M8
Caveat ID Number |
Description |
---|---|
VDS is not coming up after DNAC upgrade |
Resolved Bugs—Cisco IOS Release 15.8(3)M7
Caveat ID Number |
Description |
---|---|
RootCA intermittently does not grant SubCA renewal request even with grant auto roll ca-cert |
|
WPAN interface missing |
|
Router hangs and reload with reload reason: error - FPGA IOS watchdog timer expired |
|
DNS info received via Cellular link in VRF goes into default DNS view instead VRF Specific DNS view |
|
Communication by SVI does not recover even after the loop is resolved. |
|
CISCO1921-SEC/K9 || Router crashing frequently |
|
CGR 1xxx ciscoEnvMonSupplyState SNMP object returns Warning when DC supply is less than 12 volts. |
|
Port status looped as listening - learning - blocking with enabled STP on C921J router |
Open Bugs—Cisco IOS Release 15.8(3)M7
Caveat ID Number |
Description |
---|---|
ENH:IOS CSR (Certificate signing request) should include subjectAltName |
|
Syslog message for SIP Trunk unregistration/registration |
|
Remove NTP Core (INFO):946D 8D popcorn popcorn from ntp logging |
|
Unable to remove isakmp match statement if vrf is removed first |
|
snmp-walk output is produced when PTP is in Forward mode |
|
CUBE media issue with signaling forking for disable-early-media 180 |
|
Flow Record shows not configured even defined flow monitor |
Resolved Bugs—Cisco IOS Release 15.8(3)M6
Caveat ID Number |
Description |
---|---|
Mishandling of dsmpSession pointer causes a crash |
|
DTMF renegotiation from RFC2833 to OOB does not work |
|
CUBE fails to send outgoing SUBSCRIBE if egress dial-peer has "session server-group" configured |
|
VoIP Dial-peer up/down traps sent to SNMP server every interval |
|
CUBE - SDP version increment behaviour creates cypto interworking issues |
|
SDP version was incremented due to misplace of PT 100 |
|
IR-829 h-QOS NULL pointer deference causing a crash |
|
Recording failures with XMF media forking and SIP preservation timer |
|
MWI does not work for all shared lines |
|
491 returned on midcall INVITE when peer leg is not pending a request |
|
IPV4 Multicast packets are unexpectedly replicated to underlay interface of mGRE tunnels |
|
C3900e: crash after enabling voip translation debugs |
|
"Error in encoded data" is shown by ip nat command |
|
Memory leak in STUN/MallocLite on ISRG2 CUBE/SIP GW routers leading to memory exhaustion over time. |
|
Deleting a Voice Port on CUCM Shuts Down Additional Voice Ports on MGCP Gateway |
|
SRTP key not updated to DSP on re-INVITE |
|
I/O Memory Leak With Tunnel Config |
|
Unexpected reboot observed while trying to relay the digit to opposite leg |
|
AP 860VAE-W GUI doesn't reflect changes in WLAN Configuration. |
|
Unexpected Reload after running 'show voice dsp' command while an ISDN Call Disconnects |
|
Unexpected reload during a SIP call |
|
RTP port leak |
|
CUBE accepts SDP with invalid port number |
|
Empty VoiceXML Property Value breaks Audio even when validating syntax success. |
|
HSRP group id 11 can't create virtual MAC |
|
ISR Gen-2 fails to reset ROC on receiving new SDP parameters in SRTP hold/resume after 15 minutes |
Open Bugs—Cisco IOS Release 15.8(3)M6
Caveat ID Number |
Description |
---|---|
Remove NTP Core (INFO):946D 8D popcorn popcorn from ntp logging |
|
IP host Port lookup is failed in case of Reverse SSH |
|
Unable to remove isakmp match statement if vrf is removed first |
|
Connect message is never forwarded to the calling side |
|
RIP stops working after issuing no network 0.0.0.0 command |
|
CUBE media issue with signaling forking for disable-early-media 180 |
|
NAT stopped working with multicast |
Resolved Bugs—Cisco IOS Release 15.8(3)M5
Caveat ID Number |
Description |
---|---|
IP TUNNELS: Overlapping Loopback Interface Causes Incorrect Forwarding Decision with AppNav and PfR |
|
Crash in XDR process: "fib_rp_table_broker_encode_buf.size <= FIB_RP_TABLE_BROKER_ENC_BUF_SZ" |
|
MPLSoFlexVPN: Hub doesn't forward resolution req when default route is advertised to spokes |
|
PfRv3: Crash while Printing the Same TCA Message |
|
BFD flaps everytime with dynamic tunnel creation in DMVPN |
|
Tunnel PMTUD not being aged out after PMTUD ager timer expires |
|
%IR800_SPI_FLASH-3-VERIFY_ERROR: SPI Flash verification error at block 0x900000 |
|
Crash at Process = SCCP Auto Config |
|
Router crashes after snmpget to OID related to NHRP |
|
Performance Monitor crash |
|
Crash on "BGP Router" process |
|
ISR4K Unexpectedly Reboots with CENT-BR-0 |
|
After firmware upgrade to version 15.9(3)M1, AP is not booting |
|
C800 with multiple 'main' regions do not successfully write all cores via 'exception core-file' |
|
C841-WIM-1T DTE does not raise RTS signal |
|
5900 Series: Running config get cleared with random power cycles |
|
IBGP paths getting marked as RPKI Valid |
|
NTP crash with empty peer list |
|
IOS-XE DHCP server creates option 125 with invalid format |
|
Packet drop in vdsl controller pppoe stuck in PADISNT |
|
Cat4K sends RA with incorrect packet format |
|
EIGRP hello packets sourced from the tunnel ip address even the EIGRP is not enabled on interface |
|
IOS ISR Router crashes with "show crypto pki cert verb" |
|
Reload when applying event manager policy to the router. |
|
x509 SSH authentication incorrect UPN value selected |
|
CUBE is not able to transfer the call |
|
RTP/SRTP interworking fails when 180 and 183 have different to-tag |
|
PKI CLI - no warning that rsakeypair name starting from 0 (zero) is not working for cert regenerate |
|
CLI parser unexpectedly interprets backslash with octal numbers |
|
CUBE does not accept channel ID for MRCPv2 |
|
[C891F/15.9(3)M1] DMVPN after removing IPSec, packet drops continues at tunnel int |
|
Rpl route-poisoning not working in startup-config |
|
C927/C926 "show controller vdsl 0" hangs when MAC address is confogured on Eth 0 interface |
|
Evaluation of CVE-2020-11868 for IOS |
Open Bugs—Cisco IOS Release 15.8(3)M5
Caveat ID Number |
Description |
---|---|
Cisco IOS allows RC4-MD5 and RC4-SHA1 SSL ciphers to be negotiated by default |
|
After upgade to 15.9-3M1, GOS is using secondary IP on svcbr_0 for NAT |
|
Unexpected Reload while processing calls using H323 |
|
IOS router crashes with Crypto PAK's unavailable error from crypto engine. |
|
WCCP ACL programming issue - denied traffic is redirected |
|
VXML voice gateway crash due to block overrun |
|
NTP is unable to synchronise even when NTP messages are exchanged |
Resolved Bugs—Cisco IOS Release 15.8(3)M4
Caveat ID Number |
Description |
---|---|
C897VAW-E-K9 // 15.7(3)M1 // Unable to disable lldp |
|
Observing Memory leak at Sip MPA |
|
IR829 4G: Inserting antenna/SIM in SLOT1 disables IP connectivity on a working intf Cell 0/0 |
|
BGP labels not propagated |
|
IR807G-LTE-GA-K9 is not recognized as Cisco genuine product |
|
CGR1000 - FE LEDs and SVI incorrect behavior |
|
SIP Profiles not properly modifying 400 responses |
|
Cisco IOS and Cisco IOS XE Software Web UI Cross-Site Request Forgery Vulnerability |
|
LTE failover timer resets to 5 min after reload |
|
freed rpi_parent is hit when deleting parent route by route update event |
|
Router reload due to command "show control-plane host open-ports" |
|
VG450: SCCP crashing router while shutdown the process |
|
Unregistered supplicant can ping every re-authentication timer with mab when Spanning is disabled |
|
DHCP CLIENT not working when CWMP agent is enabled |
|
CGR1000 has SNMP queue length on 1 by default since 15.8(3)M2 |
|
router crash and reload due to freeblock magic number corruption |
|
Subinterface reporting more traffic than physical interface |
|
c927 c926 c921 usb flash drive/memory Stick problem |
|
Device Becomes Unresponsive when Running "crypto key generate rsa" |
|
IOS Firewall crash with video call |
|
SNMP cannot poll LLDP neighbors from the device |
|
ISR c800 is not giving DHCP address when port authentication failover from MAB to guest-vlan |
|
Cisco Wave 1 AP Software reloads unexpectedly when configuring a long SNMP-server community string |
|
PoE stops working after upgrade on C881K9 |
|
C921J-4P: Layer3 port(Gi4 and Gi5) linkup failure when peer is in fixed mode(speed or duplexity) |
|
Trackbacks observed when querying DNS to ipv6 link local address. |
|
System power-off after removing CLI for ignition undervoltage threshold |
|
IR829: "lte event rssi onset mib-trap" is not recognized |
|
(CRM: 00942794) IR829: link-recovery does not work after "test cellular 0 modem-reset" |
|
IPSEC stateful redundancy - show crypto ipsec sa shows PFS (Y/N): N, while active shows PFS (Y/N): Y |
|
MRCP/ASR completetimeout voicexml properties in form element is not being sent in RECOGNIZE |
|
Router crashed on removing trustpoint on dspfarm profile |
|
Ping Fails after SW-port is configured on interfaced |
Open Bugs—Cisco IOS Release 15.8(3)M4
Caveat ID Number |
Description |
---|---|
DTMF renegotiation from RFC2833 to OOB does not work |
|
CUBE fails to send outgoing SUBSCRIBE if egress dial-peer has "session server-group" configured |
|
CUBE - SDP version increment behaviour creates cypto interworking issues |
|
SDP version was incremented due to misplace of PT 100 |
|
SIP phone paging party hears own voice |
|
Packet drop in vdsl controller pppoe stuck in PADISNT |
|
SNMP OID giving inaccurate/no updates for Cellular and interface OIDs |
|
Block Overrun after NHRP-3-PAKERROR syslog message |
|
MWI does not work for all shared lines |
|
491 returned on midcall INVITE when peer leg is not pending a request |
|
Connect message is never forwarded to the calling side |
Resolved Bugs—Cisco IOS Release 15.8(3)M4
Caveat ID Number |
Description |
---|---|
C897VAW-E-K9 // 15.7(3)M1 // Unable to disable lldp |
|
Observing Memory leak at Sip MPA |
|
IR829 4G: Inserting antenna/SIM in SLOT1 disables IP connectivity on a working intf Cell 0/0 |
|
BGP labels not propagated |
|
IR807G-LTE-GA-K9 is not recognized as Cisco genuine product |
|
CGR1000 - FE LEDs and SVI incorrect behavior |
|
SIP Profiles not properly modifying 400 responses |
|
Cisco IOS and Cisco IOS XE Software Web UI Cross-Site Request Forgery Vulnerability |
|
LTE failover timer resets to 5 min after reload |
|
freed rpi_parent is hit when deleting parent route by route update event |
|
Router reload due to command "show control-plane host open-ports" |
|
VG450: SCCP crashing router while shutdown the process |
|
Unregistered supplicant can ping every re-authentication timer with mab when Spanning is disabled |
|
DHCP CLIENT not working when CWMP agent is enabled |
|
CGR1000 has SNMP queue length on 1 by default since 15.8(3)M2 |
|
router crash and reload due to freeblock magic number corruption |
|
Subinterface reporting more traffic than physical interface |
|
c927 c926 c921 usb flash drive/memory Stick problem |
|
Device Becomes Unresponsive when Running "crypto key generate rsa" |
|
IOS Firewall crash with video call |
|
SNMP cannot poll LLDP neighbors from the device |
|
ISR c800 is not giving DHCP address when port authentication failover from MAB to guest-vlan |
|
Cisco Wave 1 AP Software reloads unexpectedly when configuring a long SNMP-server community string |
|
PoE stops working after upgrade on C881K9 |
|
C921J-4P: Layer3 port(Gi4 and Gi5) linkup failure when peer is in fixed mode(speed or duplexity) |
|
Trackbacks observed when querying DNS to ipv6 link local address. |
|
System power-off after removing CLI for ignition undervoltage threshold |
|
IR829: "lte event rssi onset mib-trap" is not recognized |
|
(CRM: 00942794) IR829: link-recovery does not work after "test cellular 0 modem-reset" |
|
IPSEC stateful redundancy - show crypto ipsec sa shows PFS (Y/N): N, while active shows PFS (Y/N): Y |
|
MRCP/ASR completetimeout voicexml properties in form element is not being sent in RECOGNIZE |
|
Router crashed on removing trustpoint on dspfarm profile |
|
Ping Fails after SW-port is configured on interfaced |
Resolved Bugs—Cisco IOS Release 15.8(3)M3b
Caveat ID Number |
Description |
---|---|
DHCP CLIENT not working when CWMP agent is enabled |
|
c927 c926 c921 usb flash drive/memory Stick problem |
Open Bugs—Cisco IOS Release 15.8(3)M3b
Caveat ID Number |
Description |
---|---|
HCD_TRANS :VERBOSE error seen with USB OIR |
Resolved Bugs—Cisco IOS Release 15.8(3)M3
Caveat ID Number |
Description |
---|---|
SSL handshake failure when validating certification with name-constraints |
|
Y2.02K: self-signed cert expires after 31 Dec 2019, cannot be created after 1 Jan 2020 |
|
High CPU due to Alignment Corrections - SMEF & IWAN |
|
Rekey Timer are same for both the Server and Client |
|
Crash when entering username with aaa common-criteria policy password |
|
IPSEC NAT-T / transport mode: UDP checksum not updated on decryption |
|
Certificate map does not work always with UPN in SAN field |
|
Layer 2 Neighbors Have No Connectivity Despite Authentication Open Being Configured |
|
PKI "revocation check crl none" does not fallback if CRL not reachable |
|
PnP Agent should detect image upgrade scenario and configure dialer to bring up cellular interface |
|
Packet drop occurs after acl permit configurations |
|
Call is not getting connected in Forking Re-INVITE scenario |
|
9200L Day0 setup not working out of box. |
|
PKI incorrect fingerprint calulation during CA authentication |
|
CUBE picks incorrect interface for media after receiving c=IN IP4 0.0.0.0 |
|
Analog phones on VG310 play continious BEEP tone approx every 60 secs. |
|
Deleting one sip-copylist will remove all sip copy-lists from dialpeers |
|
IPSec-Session count in "show crypto eli" reaches max causing VPN failure |
|
Reverse SSH bringing down RTS on serial interface |
|
Flexible NetFlow Template ID is not getting exported |
|
Transcoder getting invoked for SRTP-SRTP calls. |
|
%PERF_MON_ASYNC-3-MEM: Memory cleanup failed - ssrc db cache results in PMI not created on BR |
|
Bytes output in show policy-map is incorrect on dialer interface |
|
Overlay BGP down when configured "ip nhrp server-only" |
|
Router loses "transport tcp tls v1.0" on reload |
|
"mac-address-table secure sticky <mac-add>" lost when configure "mac-address-table secure maximum" |
|
PNP profile using hostname is not working anymore |
|
Tail drops on IPSLA sender when using scaled udp-jitter probes |
|
ISR8xx TCAM limitation |
|
Shut down interface Wlan-GigabitEthernet0 |
|
ESR crashed with Segmentation fault on Process Rate limit load process |
|
Source Filter and Voice RTP Source-Filter in IOS Routers should allow RTP when on Hold |
|
VG3x0 - groundstart voice-port configuration removed after reload |
|
Reload when importing certificate from nvram: |
|
IPsec SA installation fails with simultaneous negotiations despite fix for CSCve08418 |
|
After receiving 491, cube is not setting the media transcoder flag at SRTP leg |
|
C5915 - NVRAM corrupts during bootup |
|
Crash after Media monitor look up. |
|
ISRG2: SRTP information not passed in Outgoing 183SP's SDP in external call forward scenario |
|
Split DNS not working in case of TCP query coming on WAN interface and destined to LAN interface |
|
ISDN memory leak |
|
C921 forward packets with a destination MAC address that is not the MAC Address of SVI |
|
[C900] traffic cannot be forwarded once storm-control changed from blocking to forwarding |
|
C841M (15.8(3)M2) stuck at Splash Screen when access GUI (3.5.3) via Google Chrome & Firefox. |
|
When the traffic rate is increased , VDSL interface starts bouncing |
|
C926 and C927 will have VDSL down when mac address on Ethernet interface is changed |
Open Bugs—Cisco IOS Release 15.8(3)M3
Caveat ID Number |
Description |
---|---|
IOS/XE NTP synchronized but clock drifts |
|
Evaluation of sce for NTP_January_2016 |
|
Evaluation of sce for OpenSSL January 2016 |
|
Evaluation of sce for OpenSSL March 2016 |
|
Evaluation of sce for OpenSSL May 2016 |
|
Evaluation of sce for NTP November 2016 |
|
Evaluation of all for May CPU Side-Channel Information Disclosure Vulnerabilities |
|
3650 mab failover does not work after first failed dot1x authentication |
|
Memory leak observed in AFW_Redirect_New with call transfer recall FIT1 script |
|
DTMF renegotiation from RFC2833 to OOB does not work |
|
Crash caused by a "TLB Modification exception" after processing a null chunk in "IP Input" process. |
|
"show isis rib <A.B.C.D> <A.B.C.D>" command returns % Ambiguous command: error |
|
CUBE fails to send outgoing SUBSCRIBE if egress dial-peer has "session server-group" configured |
|
CUBE changing the payload for content sharing packets, though it negotiate correctly |
|
RPHY: RPD reports 66070209 L2TPv3 Connection Error unexpectedly |
|
CUBE - SDP version increment behaviour creates cypto interworking issues |
|
Disable MOP by default |
|
Dialog Manager(url_parse_generic) leak observed in call transfer recall FIT2 script |
|
ISDN calls being picked in round robin manner instead of all happening at the same time |
|
SDP version was incremented due to misplace of PT 100 |
|
VRF routes disappeared after reload |
|
"ivr: hdata" leaks in b-acd callq scenario when audio files are not present in configured path |
|
SIP Profiles not properly modifying 400 responses |
|
Exporter Thread crash after low stack report |
|
SIP phone paging party hears own voice |
|
T-Train: Hung calls found on standby router |
|
Packet drop in vdsl controller pppoe stuck in PADISNT |
|
SNMP OID giving inaccurate/no updates for Cellular and interface OIDs |
|
ezvpn client config dissapears from gig0 interface when interface flaps |
Resolved Bugs—Cisco IOS Release 15.8(3)M2
Caveat ID Number |
Description |
---|---|
Rework for CSCun57148 - High CPU in FNF Cache Ager P |
|
crash after no ipv4 multicast multitopology command |
|
High CPU Due to "Async write proc" During Hung Filesystem Operation |
|
Polaris_dev 16.6: IOSd crash @act2_token_engine_message_proc with flexvpn profile |
|
Memory leak Crypto IKEv2 at ikev2_ios_psh_set_route_info |
|
Traceback seen at sdp_verify_sdp_ptr |
|
DTMF fails when mid-call renegotiation changes DTMF method |
|
Watchdog crash within mgcpapp_free_sys_event_Q event dequeue loop after running 'ccm-manager config' |
|
memory leak @ CCSIP_SPI_CONTR |
|
CUBE: FPI Hung Sessions and Provisioning Failures observed in Standby CUBE |
|
BGP Traceback/Crash seen with 20k IPv4 BGP scale after reload/clearing bgp |
|
Router fails to reserve necessary ports for VPN traffic (UDP 500 & 4500) for ISAKMP |
|
CUBE crashes at sipSPI_ipip_vcc_CheckCodecSetType |
|
ISDN PRI calls getting dropped with cause 47 because of bad interaction between CDAPI and TSP layers |
|
Device crashed when call-home is enabled and non-ascii characters in use in login banner |
|
"clear crypto sa vrf MyVrf" triggers crash after updating pre-shared-keys |
|
IPV6 prefix delegation issue in 881 router |
|
BGP updates missing ISIS advertising-bits led to LDP label purge on peer. |
|
Crash under AFW_application_process with shared-line configuration |
|
Crash at CCB of RTPSPI at the moment of creating a disconnect timer |
|
[EIGRP] a summary route is updated by an external route |
|
ASR-CUBE: Crashes with call spike configuration changes |
|
PKI authentication should proceed even if GetCACaps return any http failure |
|
IOS-XE CUBE HA Crash with re-invite audio call escalated to video |
|
IPSec background crash while sending SNMP trap |
|
CUBE: Crash observed at rbuf_ooh_handler |
|
WATCHDOG with DHCP Client |
|
IP change on dialer-int does not trigger a correct "local cryto entpt"in DMVPN |
|
DSM-3-INTERNAL: Internal Error : No DSM handle provided traceback on TDM voice gateway |
|
BGP update not properly processed by inbound route-map |
|
CUBE Crash in sipSPIAppAddCallInfoUI |
|
Entry level conference register getting hung, resulting into no hardware conference |
|
CUBE Crashes in SRTP-RTP call flows because of CSCvf93129 commit ( Needs rework) |
|
iWAN router PDP crash on HUB MC due to PLR interface flapping w/o other available path |
|
Crash with SIP call |
|
loss of two way audio with Skinny Phone, Line instance does not work until the next reboot. |
|
Router Crashes When PKI-CRL-IO_0 Runs out of Stack Space During Failed DNS Lookup for CA Server |
|
CUBE incorrectly fomats SIP SDP with Content-Length > 1024 |
|
Cube crash with %SDP-3-SDP_PTR_ERROR |
|
CUBE-HA: Standby CUBE reports error VOICE_HA-3-DATA_RECREATE_ERR: (STBY-Create) in CCAPI module |
|
ISR4331 Routers May Crash When "eigrp default-route-tag" Configured on IPv4 AF |
|
Removal of loopback interface causes router to crash and erases the conf register settings |
|
Crash when making voice call via sip trunk |
|
Crashed when type 'no service dhcp' with router use DHCP static binding file in DHCP pool |
|
SSRC-field in RTCP gets changes to 0 when going through TRP present in the media path. |
|
CUBE doesn't forward INVITE with "midcal-signalling passthru media-change" during a video escalation |
|
Recommit of CSCvm99778 - eca/ewlc/qwlc/mewlc Sanity : AP join failed. |
|
Router may experience a crash on process CENT-BR-0 when receiving an internal update |
|
RTP/SRTP interworking fails when 18x w/o SDP is before 183 w/SDP |
|
CUBE not doing session refresh, and not accepting the refresher in 200OK for the INVITE. |
|
Modified EIGRP timers on Virtual-Template put all associated Vi interfaces into passive mode |
|
iWAN domain password is overwritten by the global password, "password encryption aes" |
|
Crash when making an external call |
|
Flash corruption results in endless loop in dfs_init_inodetable |
|
CUBE strips '+' sign from the called number in the outgoing INVITE. |
|
IWAN Crash When Accessing Invalid Address |
|
FlexVPN with password encryption - keyring aaa LIST password 6 xxxxx encrypted again upon reload |
|
Crash closing background connections by form-based Webauth |
|
Second modem on IR829-2LTE-EA-AK9 configuration lost after reload and going back to default settings |
|
SIP global binding disappears when the interface to which SIP is bound flaps. |
|
SRST Parallel hunt group fails if first member missing |
|
SCCP Application does not clear failed sockets leading to leak and socket pool exhaustion |
|
Mesh key generation must fail if the Virtual-WPAN interface is not yet up. |
|
Chunk corruption crash when processing packet in CSDB_TCP_LISTEN state |
|
Input Queue Wedge due to cTCP |
|
Router crashing after upgrade due to Crypto commands "Block overrun at 284B2160 (red zone 000110DF)" |
|
Router crashes after running "show interfaces transceiver detail" |
Open Bugs—Cisco IOS Release 15.8(3)M2
Caveat ID Number |
Description |
---|---|
ASR1K/RP2/SW 15.4(3)S4 crash |
|
ISM-VPN: double counting of SNMP ifInOctets on sub-int with crypto map |
|
FlexVPN: remote auth method isn't accepted in ikev2 profile |
|
IKEv2 - Signature sign, verify failures seen with 4096 bit certificates with onboard crypto engine |
|
Running "show usb device" command causes switch crash |
|
Redundancy inter-device is not working with "security ipsec" |
|
ASR920: EC-5-MINLINKS_MET syslog is not generated |
|
IPv6 ping fail, with VRF route leaking |
|
config revert Rollback visible in console and locks up config from VTY |
|
Port channels interface counters show decrement for CRC errors |
|
Memory leak VOIP *MallocLite* |
|
C881G-4G: Normal buffer leak with: pak_copy_network_start_particlized - cont #2. |
|
Crash when entering username with aaa common-criteria policy password |
|
Crash caused by a "TLB Modification exception" after processing a null chunk in "IP Input" process. |
|
CUBE fails to send outgoing SUBSCRIBE if egress dial-peer has "session server-group" configured |
|
QSIG - SIP - Connected Number Missing leading digit when decoding raw QSIG |
|
CUBE changing the payload for content sharing packets, though it negotiate correctly |
|
Standby reloads continuously in VSS if the configuration contains AES encryption and macsec (CTS) |
|
BFD PP Process Crashes in Timer Wheel Replenish |
|
CUBE - SDP version increment behaviour creates cypto interworking issues |
|
CUBE DNS SRV Query is not performed for PRACK |
|
"%IR800_SPI_FLASH-3-VERIFY_ERROR: SPI Flash verification error at block 0x900000" |
|
IPSec-Session count in "show crypto eli" reaches max causing VPN failure |
|
Reverse SSH bringing down RTS on serial interface |
|
Flexible NetFlow Template ID is not getting exported |
|
Transcoder getting invoked for SRTP-SRTP calls. |
|
Virtual-Access may lead to packet drops with code IN_US_V4_PKT_FOUND_IPSEC_NOT_ENABLED |
|
%PERF_MON_ASYNC-3-MEM: Memory cleanup failed - ssrc db cache results in PMI not created on BR |
|
Bytes output in show policy-map is incorrect on dialer interface |
|
SSH sessions stuck at ESTAB |
Resolved Bugs—Cisco IOS Release 15.8(3)M1
Caveat ID Number |
Description |
---|---|
IOS PKI: trustpoint doesn't rollover regenerated RSA keys. |
|
Different Interface Error Counter Results On Two Interfaces |
|
SNMP memory leak observed with snmp-server host configuration |
|
RSP2_System_THS:traceback observed after standby RP upgrade in ISSU |
|
FlexVPN: Hostname in DHCP is incorrect when using AnyConnect |
|
897: CFM syslog messages not displayed |
|
Memory leak under LLDP Protocol process |
|
VXML GW hardening changes for ICBC memory corruption issue |
|
Line-by-Line sync verifying failure on command: client test01 server-key 0 Password |
|
IPsec/IKEv2 Installation Sometimes Fails With Simultaneous Negotiations |
|
Rogue NA messages are corrupting ipv6 neighbor table. |
|
CBR8 enhancements for cable nd validate feature |
|
voiprtp_register_transport_port_manager_and_reserve: Alloc ports failed, min: 8000, max: 48199 248 |
|
"ip dfbit set" command is not present under l2tpv3 pseudowire-class for platform C891F-K9 |
|
Traceback is observed during mid-call media IP and port change |
|
Anyconnect: Hairpinning fails with cef enabled |
|
PFRv3 Incorrect reported value of TCA threshold in traffic-class router change history |
|
Standby switch crashes when flow-exporter destination configured with Hostname |
|
RADIUS client on network fails to solicit PAC key from CTS even though the device has a valid PAC |
|
CME: Toll fraud app not automatically trusting traffic from phones |
|
CNS Exec process crash @ cns_get_config_from_server |
|
Backup path incorrect for ring topology where high ISIS cost is configured on 1 link. |
|
ospf routing loop for external route with multiple VLINKs/ABRs |
|
Path of Last Resort Sending Probes in Standby State |
|
mtu cli is disappeared from show run when interface dialer sh/no shu |
|
Zero Touch Provisioning (ZTP) fails to apply certain service instance configuration. |
|
PKI:-IP address parsing issue while printing the subject name if classless IP is used in Trustpoint |
|
CSR1k-FlexVPN: Spoke to Spoke: Implicit NHRP entry due to expired resolution request handling. |
|
Crashed due to process = IPSec background proc |
|
"ip address dhcp" may disappear from configuration affecting forwarding capability |
|
OSPF neighbor stuck in loading after VSS switchover |
|
CUBE is using wrong source IP address to send SIP error |
|
Secure CME/SRST router with PRI/BRI not able send or receive calls |
|
491 not sent in a multiple re-invites in DO2EO scenario |
|
X25 translation failing on cisco 2900 router |
|
ISAKMP using UDP500 rather peer(translated) port from peer structure while initiating IKE SA for DPD |
|
Memory corruption at PKI Session End |
|
High Availability system with two Voice Gateways - Crash |
|
C887: Ports stay in down state after software upgrade |
|
Lisp router crash with enabling IPv6 and DHCP relay. |
|
Router crash - AFW_application_process |
|
Change the order of BYE and NOTIFY with 200 OK sipfrag body for successful REFER passthru scenario |
|
Initial contact in IKEv1 phase 2 rekey (QM1) causes all crypto sessions to drop |
|
[3945e] VXML gateway crash @ mrcp functions |
|
Extension Mobility Not working when used with Greek locale on SIP CME |
|
No calls shown in output "show call active voice brief" on CUBE & stale entries are present |
|
PMIPV6: Tunnel information on MAG for a GRE IPv6 tunnel shows invalid IPv4 addresses |
|
Incorrect Contact port 5060 used instead of 5061 by CUBE in "302 Moved Temporarily" message |
|
Rework need on CSCvj59170 to support SDP parsing |
|
CRL file is getting overwritten when PKI server turns up after reload |
|
One-way audio to IP phone if phone does hold/resume after 20 minutes on secure SIP GW |
|
Crash due to out-of-memory condition, huge Memory @CENT-BR-0 |
|
SNMP queue full error on a router with VDSL controller |
|
CFD: PNP DNS discovery with trust pool flow uses IP address in PNP profile instead of FQDN |
|
iBGP PE-CE When Route-Reflect enable VRF import all Route Target. |
|
On 'outbound' dial-peer with 'session server-group' , call forward returns 503 SIP error . |
|
IOS CUBE Ent does not show 'media anti-trombone' in configuration |
|
SIP CME Crashes when Calling Shared Line |
|
"VoIP dial-Peer <XX> is Busied out" printed in log every 2 minutes when destination is not reachable |
|
VXML GW with Nuance SpeechSuite 10.X or11.X, MRCPv2 recordutterance / SaveWaveform failure |
|
G2 IWAN TC Class not Maintained |
|
SNMP OID conflict.Trap being generated with wrong oid 6999.it should be 854 |
|
IR 829 Not able to bring up gig0 with SFP-mudule GLC-SX-MM-RGD |
|
Not able to enable the CLI http-status-code-ignore |
|
CUBE doesn't forward 200 OK in SRTP-RTP scenario with TCL script on Dial-peer |
|
ISR 4431 GW crashed due to flex_dsprm_vtsp_close |
|
IOS and IOS-XE STCAPP service not updating DTMF RFC2833 payload when there is SCCP renegotiation |
|
1 way audio as voice dialpeers associate with wrong VRF id after a data interface Dialer wVRF flaps |
|
CUBE Crash in CCSIP_SPI_CONTROL process |
|
Memory leak at __be_crypto_acl_lookup_v4_hit_count_handle |
Open Bugs—Cisco IOS Release 15.8(3)M1
Caveat ID Number |
Description |
---|---|
IOS/XE NTP synchronized but clock drifts |
|
Evaluation of sce for NTP_January_2016 |
|
Evaluation of sce for OpenSSL January 2016 |
|
Evaluation of sce for OpenSSL March 2016 |
|
Evaluation of sce for OpenSSL May 2016 |
|
Traffic export (RITE) corrupts the copied packets received on a vDSL/PPPOE interface |
|
Evaluation of sce for NTP November 2016 |
|
High CPU Due to "Async write proc" During Hung Filesystem Operation |
|
Memory leak under Chunk Manager / Firewall State |
|
High CPU due to Alignment Corrections - SMEF & IWAN |
|
Device-Sensor accounting TLVs not supported in ISR |
|
Device crashed when call-home is enabled and non-ascii characters in use in login banner |
|
Crash when entering username with aaa common-criteria policy password |
|
PKI authentication should proceed even if GetCACaps return any http failure |
|
WATCHDOG with DHCP Client |
|
IR807G-LTE-VZ-K9 radio low power mode |
|
IP change on dialer-int does not trigger a correct "local cryto entpt"in DMVPN |
|
FlexVPN MPLS - label in CEF not added when shortcut to hub is created (by glitch) |
|
Crash caused by a "TLB Modification exception" after processing a null chunk in "IP Input" process. |
|
crash because of function "flow_exp_v5_new_pak" |
|
IPSEC NAT-T / transport mode: UDP checksum not updated on decryption |
|
Router Crashes When PKI-CRL-IO_0 Runs out of Stack Space During Failed DNS Lookup for CA Server |
|
Certificate map does not work always with UPN in SAN field |
|
CUBE incorrectly fomats SIP SDP with Content-Length > 1024 |
|
Crash when making voice call via sip trunk |
|
Crashed when type 'no service dhcp' with router use DHCP static binding file in DHCP pool |
|
SSRC-field in RTCP gets changes to 0 when going through TRP present in the media path. |
Resolved Bugs—Cisco IOS Release 15.8(3)M0a
Caveat ID Number |
Description |
---|---|
SMS triggers cellular modem crash. |
Resolved Bugs—Cisco IOS Release 15.8(3)M0b
Caveat ID Number |
Description |
---|---|
Crash seen when peer-group cmds are issued with bmp server configured |
|
Eigrp hmac-sha-256 secret string changes when show running-config is executed |
|
Hub MC continues to send EIGRP SAF hellos after adjacency removed |
|
ASR1K BGP scanner crash when change VRF and BGP configuration |
|
load-balance advanced moving traffic to fallback path when primary path are not over utilized |
|
iwan router crash while updating pmi policy |
|
PFRv3 Incorrect time-stamp in traffic-class router change history |
|
DMVPN: Crypto session stuck into UP-IDLE status after reconfiguring tunnel |
|
There is junk entry in route-import table on branch when shutdown/no shutdown WAN interface |
|
Wrong initial number of DPD incrementing error counter. |
|
Local LAN-only prefix present in master route-import table but not present in site prefix DB |
|
VAI Leaks with IKEv1 DVTI |
|
iBGP dynamic peer using TTL 1 |
|
PFRv3 route-control is inconsistently set to "Disabled" on BR devices |
|
Ensure load-balance internet TC's don't match 'class DEFAULT' if configured |
|
Standby RP crashes due to Memory usage in ospf_insert_multicast_workQ |
|
ASR1K Datapath is not passing CTS tagging over PfRV3 auto-tunnel with "cts sgt inline" |
|
Protocol type for GRE header doesn't work consistently with "cts sgt inline" enable over auto-tunnel |
|
Static configured prefix should be able to override old one for branch site-id change migration case |
|
link local multicast packets are received when the SVI is in down state |
|
default channel operation state changing from I/O to D/O failed when zero-sla enabled |
|
Memory leak@CENT-BR-0 when change the path label frequently |
|
OSPF originates default route without "default-information originate" |
|
Path of Last Resort Sending Probes in Standby State |
|
PfRv3: BR May Crash due to Channel Creation/Modification and Next-Hop State (Copied from CSCva72274) |
|
Directly connected IPV6 connectivity broken 800 series router |
|
bgp crash while running show command and same time bgp peer reset |
|
ISIS for IP is enabled/installing routes in the RIB while IP routing is disabled |
|
Branch BR crashed at cent_rpi_parent_del_user_ctx_by_ref with branch scale test |
|
C800 : LLDP-MED packets have network-policy TLVs with DSCP 0 value by default |
|
CUBE incorrectly fomats SIP SDP |
|
CUBE is not responding to SIP INFO |
|
Crash due to out-of-memory condition Memory leak@CENT-BR-0 |
Resolved Bugs—Cisco IOS Release 15.8(3)M
Caveat ID Number |
Description |
---|---|
IP SLA http operation with customizable status for return codes |
|
Map doesn't get updated with socket change on local address change |
|
router crash while connecting to the camera on the NAT enabled interface |
|
Spike seen in SLCP process due to specific OIDs being polled by SNMP |
|
call-home crash because calling XOS API in interrupt level |
|
Config Sync failure with Call-home, reporting smart-licensing-data |
|
Traceback is seen when a EEM script runs |
|
Cisco IOS and Cisco IOS XE Software IPv6 SNMP Message Handling Denial of Service Vulnerability |
|
ikev2 fragmentation not working with aes-gcm encryption - hmac failure |
|
Double-free of VTY context causes a software-forced crash |
|
IOS Crash in Timer Wheel Tick on High Timer Churn |
|
wrong EIGRP redistribution statement in startup config breaks BGP settings atfer router reload |
|
Excess BGP Traps Generated just after upgrade |
|
EEM applet will not release the Config Session Lock if it ends when CLI is in configuration mode |
|
Crash after IWAN does a recalculation in the RIB |
|
High CPU utilization due to Virtual Exec process |
|
IKEv2 when key-config key is lost, type 6 pre-shared key encrypted form is sent as pre-shared key |
|
"password encryption aes" may break redundancy |
|
Autoboot sequence suspends on repeated power toggle |
|
HTTP client source interface bind does not apply to virtual interfaces |
|
Communication through Serial port not going through RTS down |
|
Cisco IOS and IOS XE Software Plug-and-Play PKI API Certificate Validation Vulnerability |
|
891FW Wlan-GigabitEthernet8 interface down in trunk mode |
|
CUBE automatically considers re-INVITE with a=silenceSupp:off - - - - as fax call |
|
Cisco IOS and IOS XE Software IOS daemon Cross-Site Scripting Vulnerability |
|
SNMP Walk for cpmProcessEntry mib causes the crash |
|
Crash in SDP Passthru when T.38 as 1st mline in mid-call SDP |
|
Memory leak in IPSEC key engine process |
|
False "voip_rtp_allocate_port:Possible port leak" errors |
|
MIB counter for IPSec tunnels does not decrement under high tunnel scale and churn |
|
IOS-XE router crash from memory corruption during CCB cleanup |
|
IWAN EIGRP SAF - seq number mismatch after branch reload |
|
PfRv3 triggers List Header leak in FNF |
|
Hub MC get crashed@cent_mc_print_prefix_do_one when show domain iwan master site-prefix |
|
OPTIONS not replied by CUBE over TCP without interface bind |
|
After upgrade of IOS, SSH passwords longer than 25 characters do not work |
|
Router Crashes Due to Memory Corruption When Transferring Shared Line Call |
|
Crash when doing snmp walk for ipAddressEntry |
|
CUBE Duplicates Diversion Header using DNS and SIP bindings |
|
Normal buffer leak with: pak_copy_network_start_particlized - cont. |
|
Voice-port command compand-type is remove during a reboot |
|
Cisco device unexpectedly reloads after TCP session timeout |
|
ISR4K - IOSd crash with SIGABRT with CCVPM_HTSP |
|
%CGR1K_IOH_I2C-3-MUX_DANGLING: Attempt to enable MUX port no 1 while port no 1 is already enabled |
|
ISR 4K unexpected reboot with a large number of transcoding sessions |
|
3rd Party SIP Phones not registering from CME 11.6 |
|
Cube crashes intermittently multiple times within every two days. |
|
ISR 4000 discards private RSA key after upgrade and reload with WAAS module |
|
Global bind disappears when bind interface flaps during an active call |
|
Cisco IOS Software 802.1x Multiple-Authentication Port Authentication Bypass Vulnerability |
|
High CPU for 5 minutes causes DSP keepalive timeout and does not recover when using WCCP |
|
"no cdp enable" is rewritten to "no cdp tlv app" after reload. |
|
PKI: All SCEP requests fail with "Failed to send the request. There is another request in progress" |
|
Cisco Smart Install Remote Code Execution and Denial of Service Vulnerability |
|
CUBE does not acknowledge Session-Expires header in UPDATE |
|
IOS-XE GM router might crash after the rekey method is changed from unicast to multicast |
|
ISR 4k SCCP Process Does Not Wait for All PVDM Modules to Come Up Before Registering |
|
IOSd crash while applying dial peer configuration |
|
Router loses RSA keys and type 6 password encryption key upon boot with private-config encryption |
|
PKI: Device crash during crl download with multiple CDP URI |
|
ISR G2 VRF+PBR+NAT may not work with CEF under certain scenarios |
|
ISM stops forwarding IPSEC traffic / %OCE-3-OCE_FWD_STATE_HANDLE / free_ob=75000 |
|
8800 KEM module not getting detected on 88XX phones with CME 12,11.6 |
|
Output "sh sip-ua connections tcp tls detail" shows that CUBE has stuck connection ids. |
|
C841M SVI interface send redirect packet when the address doesn't exsit and it doesn't know the MAC |
|
SSH password length restricted to 25 for avoiding one of the low impact vulnerability. |
|
3650 -- high CPU due to TTY Background process |
|
router crashed after entered "no ipv6 access-class sl_def_ipv6_acl in" during quiet mode |
|
CME: SIP Notify to clear NightService display message not sent to phones during de-activation |
|
IKEv2 - Crash with segmentation fault when debugs crypto ikev2 are enabled |
|
CUBE Unsolicited NOTIFY returns 481 Subscription does not exist |
|
DHCPOFFER is routed in global instead of VRF by RELAY AGENT |
|
MGCP fallback mode remains ON after CUCM registered |
|
ISDN memory leak |
|
CPP crash stuck thread detected multikey_hash_replace_int |
|
Chunk corruption crash related to PNP or Guestshell |
|
Static NAT entry disappears from running-config with NVI nat |
|
traceback: PM-4-NOSB: No PM subblock found for interface Gi0/0 |
|
Router with SIP traffic crashes at ccsip_free_kpml_info |
|
Overruns due to nbar with bursty flows |
|
SIP stack matching the dial-peer when processing NOTIFY message causing call routing issues |
|
dialpeer matching for inbound SIP profile fails with VRFs |
|
Cisco2921 ssh/console session hung when config script runs flowcontrol hardware command |
|
VRF aware CUBE fails to send OOD OPTIONS pings |
|
Crashes seen with C2900+ISM crypto engine with high traffic rates / high CPU |
|
ACL sl_def_acl getting saved on running config |
|
PI IOSd reload due to call-home at kex_dh_hash conn pointing to eem |
|
Crash during Generic Call Filter Module cleanup |
|
MGCP status remains Down after IOS upgrade caused by CSCvh70570 |
|
High CPU utlization with presence feature, when reset is issued under voice register global |
|
Stack corruption crash on ESR |
|
Router crashes @ memcpy, mdns_read_packet |
Open Bugs—Cisco IOS Release 15.8(3)M
Caveat ID Number |
Description |
---|---|
Pushing additional config via VxWorks takes too long |
|
Cisco IOS and IOS XE Software EnergyWise Denial of Service Vulnerabilities |
|
Evaluation of sce for NTP_January_2016 |
|
Evaluation of sce for OpenSSL January 2016 |
|
Evaluation of sce for OpenSSL March 2016 |
|
ASR1K/RP2/SW 15.4(3)S4 crash |
|
Evaluation of sce for OpenSSL May 2016 |
|
Traffic export (RITE) corrupts the copied packets received on a vDSL/PPPOE interface |
|
Half duplex path streams (MoH) not established with source filter |
|
Evaluation of sce for NTP November 2016 |
|
High CPU Due to "Async write proc" During Hung Filesystem Operation |
|
MAT event not getting triggered in IE 3000 & IE4000 |
|
Memory leak under Chunk Manager / Firewall State |
|
Excessive "Reflector" Tracelogs |
|
Router crashes after loading NBAR2 protocol pack |
|
Anyconnect: Hairpinning fails with cef enabled |
|
IR809/IR829 - Possible side-channel style information disclosure vuln |
|
High CPU due to Alignment Corrections - SMEF & IWAN |
|
CNS Exec process crash @ cns_get_config_from_server |
|
GETVPN Key Servers after split may generate TEK with same SPI but different key material |
|
mtu cli is disappeared from show run when interface dialer sh/no shu |
|
%TCP-4-INVALIDTCB: Invalid TCB pointer: -Process= "Tcl Serv - tty705", ipl= 0, pid= |
|
3650 mab failover does not work after first failed dot1x authentication |
|
Router crashes as soon as it downloads the config from CUCM, ccm-manage config command. |
|
Memory leak on the Small Buffer pool due to "x25swt_last_resort" process |
|
"ip address dhcp" may disappear from configuration affecting forwarding capability |
|
DMVPN crypto packets are not egressing C891 |
|
Command 'ipv6 tcp adjust-mss 1360' does not take effect with GETVPN |
|
Directly connected IPV6 connectivity broken 800 series router |
|
Incorrect values for conformed traffic upon applying PIR values greater than 4G |
|
Secure SRST router with E1 PRI not able send or receive calls |
|
Device-Sensor accounting TLVs not supported in ISR |
|
X25 translation failing on cisco 2900 router |
|
C800 : LLDP-MED packets have network-policy TLVs with DSCP 0 value by default |
|
ACS URL not overwritten when sent from DHCP Server |
|
DSP detected FXO "supervisory disconnect dualtone mid-call" is treated as CNG tone |
|
Memory corruption at PKI Session End |
|
C841M: usb dongle modem queue stuck |
|
COOP ANN messages fail to send around the time of TEK generation |
|
C887: Ports stay in down state after software upgrade |
|
Dot1x on C886 routers fails in multi-domain mode |
|
LLDP pkt drop on intf <Intf> when disabling lldp on this interface |
|
LISP router crash with enabling IPv6 and DHCP relay. |