Email Security - Server (EX) 10.0.4 Release Notes

Prev Next

Note

Release 10.0.4 is the current release after 10.0.2 for Email Security - Server.

Resolved Issues

The following issues were resolved in the Email Security - Server 10.0.4 release.

Tracking number

Summary

COM-62557

To further harden the security of our products, we have upgraded Apache HTTPd to version 2.4.62, the latest stable release.

COM-62574

Fixes an issue where the sensor goes into unknown state after a reboot when submission metadata streaming is enabled.

COM-62575

Fixes an issue where the Helix Alert notification was not displayed.

COM-31727

To mitigate the Terrapin Vulnerability (CVE-2023-48795), the chacha20 cipher is removed from our high-security list for non-FIPS/non-CC customers using the high-security list. Now, the Trellix platform is not vulnerable to Terrapin Vulnerability (CVE-2023-48795) with default configuration. We plan to upgrade to the latest stable version of OpenSSH in the upcoming 11.0 major release to further harden and resolve the vulnerable option related to the Terrapin Vulnerability.

Known issues

The following issues are known in the Email Security - Server 10.0.4 release.

Tracking number

Summary

COM-30656

The negation symbol "!" is not functioning as expected when placed before the hostname or username in the deny user list.

COM-30655

During the concurrent execution of the alert purge, database backup operations exhibit prolonged duration.

Workaround: Stagger the scheduling of database backup and alert purge processes to avoid simultaneous execution.

COM-31165

The GI settings API does not currently enforce a limit of 10 inputs for a field.

EMPS-17820

The downgrade of Email Security - Server to a previous release resulted in the loss of data configured on the "Advanced Rule" tab of the current release.

EMPS-17781

Forward email list is empty for Exchange Remediation in 'the View Email page.

EMPS-17780

Submitting duplicate mdsum, sha256, or URL values to allowed and blocked lists via the Web UI and CLI results in inconsistent output.

EMPS-17729

Remediation of emails sent to distribution lists or aliases is not supported.

EMPS-17745

Inconsistency output are generated when duplicate values of mdsum/sha256/url are added from Web UI and CLI for allowed and blocked list.

EMPS-17730

Under eAlerts > Riskware > Alert Details page, the filename field is missing.

EMPS-17213

On upgrading to 11.0.0, Alert summary count and redirection counts are not consistent for Total Malicious Emails, Malicious URLs, and Malicious Attachments.

EMPS-17700

The EX appliance displays the following error "Application server error occurred" after running the command "system cleanup profile temp-files all".

WEBUI-29828

In the Email Quarantine tab, Badges option check boxes are greyed out in light mode.

WEBUI-29818

Introduced a loading indicator for third-party feeds within the Allow/Block lists to enhance user comprehension of data availability status.

WEBUI-15060

On the About > Create Log Archive page, logs do not appear after the success message. It requires a refresh of the UI to be visible.

WEBUI-14979

The Service Health Statistics Trend incorrectly displays date and time for weekly and monthly reports.

WEBUI-14964

Third-party feeds permit the upload of arbitrary files with STIX type from both the UI and WSAPI.

Disable SAML in a Helix environment

SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Email Security - Server appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.

For more information, see the Helix Integration Guide for Trellix devices.

  • In the Software Requirements section, see “HelixConnect Client Software Requirements”.

  • In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.

Upgrade support

The Trellix Email Security - Server 11.0.1 release requires a reboot for the update to take effect. You can upgrade your EX appliance to 11.0.1 from release 9.1.0 or later.

After an upgrade to version 10.0.4, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.

Created Log archive files on 9.1.x will not be preserved on upgrade to 11.0,0. Please have a backup of logs before upgrade.

Important

When you upgrade an Email Security appliance to 11.0.0, FireEye Advanced URL Defense Engine (FAUDE) and email feature extraction are enabled, even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" and "Enabling or Disabling Email Feature Extraction Using the CLI" in the

Email Security — Server Edition User Guide

.

Note

After an upgrade to version 11.0.0, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.

Downloading content from the DTI offline update portal

If you download Email Security - Server 10.0.4 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

YARA rules supported versions

YARA rules support version 4.3.2.

Important

Before you upgrade an Email Security - Server appliance to the 10.0.4 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.