Hi,
To my understanding the FWSMs (even though both active) have identical configurations?
Have you perhaps done so that on the core switch you have only issued the "firewall vlan-group only on the primary core device (to which the FWSM is attached) and not the secondary core device?
The only time I have witnessed the same situation is when configuring a new customer link and I have only configured the primary unit (and about to configure the same on the standby unit)
Hope it helps, not sure if the above was what you meant.
- Jouni