Central Management System 10.0.1 Release Notes

Prev Next

New features and changes

Central Management System 10.0.1 does not contain new features or enhancements.

New, modified and deprecated CLI commands

Central Management System 10.0.1 does not contain new, modified and deprecated commands.

Resolved issues

The following issues were resolved in the Central Management System 10.0.1 release.

Tracking number

Summary

CMS-16369

After upgrading to version 9.1.0, the About section of the Web UI displayed "CMSHA Fedb Sync health Disabled". This issue is resolved.

CMS-16840

Managed sensors enrollment to MVX cluster is broken on proxy enabled CMS. This issue is resolved. Managed sensors now enrolls to a local MVX cluster if the CMS enrollment service is set to "LOCAL" irrespective of cloud MVX settings.

CMS-16988

Resolves an issue where the Write to Group option failed to function properly on the 'Advanced Rules' tab.

CMS-17151

Smartvision alerts generated prior to version 9.1.3 did not display the base event details and event summary information in CMS. This issue is resolved.

CMS-17164

Unable to send email notifications from CM after upgrading to BONA 10.0.0. This issue is resolved.

CMS-17169

After upgrading to BONA 10.0.0, when you click the "Back to Events" link after searching for an event on the IPS Events page in CM, all filters are reset. This issue is resolved.

CMS-17171

The Search Emails page appears blank after selecting processed emails. This issue is now resolved.

CMS-17173

The CMS appliance fails to gather alerts when the system UUID of the appliance is not found in CMS. This issue is resolved.

CMS-17178

Resolves the issue where the system was unable to track user login activities in the web UI.

CMSHA-1566

Resolves the issue where the alert notifications were not functional due to outdated alert notification data files.

COM-31382

Fixes an issue by adding mechanism to clean up outdated triage packages.

COM-30410

Fixes an issue by removing the password present in the API response for CMS appliances.

COM-30687

The 10.0.1 appliance has upgraded Apache httpd to 2.4.56 to address a known vulnerability (CVE-2022-36760) for products including Malware Analysis, Central Management SystemEmail Security — Server, File Protect, Network Security, and Intelligent Virtual Execution - Server.

COM-31481

Fixes an issue that, by default, upgraded all the Central Management System appliance applications to the high-security factory default cipher-lists.

COM-31615

The CMS appliances are not vulnerable to CVE-2023-5072.

COM-31650

Fixes an issue that prevented the "show alerts type all detail concise timeframe <>" CLI from displaying alert details.

Known issues

The following issues are known in the Central Management System 10.0.1 release.

Tracking number

Summary

CMS-17150

Manually populating the CMS cache through the command-line interface (CLI) is not functional.

CMS-17185

The Network Security Domain whitelist under the General tab is not displayed in CMS appliance settings.

CMS-17198

CMS Web UI displays the "IPS policy out of sync" status even when the IPS policy is actually synchronized across NX instances running various releases.

CMS-17200

CVE values are displayed incorrectly on IPS events main page for IPS events with same signature_iden and signature_rev.

CMS-17206

Hitting back to IPS events clears date and time filters in ips event search.

CMS-17221

The drop-down list of appliances shows a list of non-EX LMSs and non-supported EXs.

CMS-17224

'Delete' is disabled for 'Write to Group' for 'Advanced Rules' tab.

CMSHA-1560

The show health system CLI must not return "Disabled" and "Node is not primary" for CMSHA fedb sync health service on CMSHA.

CMS-15046

Sometimes, PCAP files fetched from the Network Security appliance contain zero bytes when the number of concurrent CMC file transfers reaches the maximum system limit.

CMS-15792

The MVX-correlated IPS alerts are not deleted in the Central Management System appliance after the cleanup.

CMS-16379

The following messages are displayed in the Central Management System appliance Web UI: "Unable to read version info to figure out correct server manifest file" and "Failed to load master manifest" mgmtd.WARNING". You can ignore these error messages.

CMS-17093

The alert hyperlink in a quarantined message for riskware doesn't redirect to the corresponding riskware alert.

CMS-17133

On the Central Management System Web UI Analysis page, the current running submission should not be displayed as a child of a completed submission.

COM-30639

Credentials in the login page are transmitted over the SSL layer in plain text without encoding.

COM-30405

SAML Response decoding sometimes fails with IDP.

The appliance displays a "bad encoding" error when the system's IDP response contains carriage return and newline characters.

COM-30655

The database backup process takes a long time when the alert purge is in progress.

Workaround: Schedule the database backup and purge processes at different times.

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

COM-30659

Alert details might be missing from the report generated during alert purging.

Upgrade support

The Trellix Central Management System 10.0.1 release requires a reboot for the update to take effect. You can upgrade your CMS appliance to 10.0.1 from release 9.0.0 or later.

IPMI and BIOS firmware updates are required for the CM 4500 model. See the following section "Upgrading IPMI 3.11 and BIOS 1.9 Firmware for Specific Platforms".

Note

After an upgrade to version 10.0.1, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Upgrading MVX clusters

Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-9.1.0 release to 10.0.1 is not supported. Follow the procedure in this Community article to upgrade your MVX clusters.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.1.

Downloading content from the DTI offline update portal

If you download Central Management 10.0.1 security content from the DTI Offline Update Portal, use the SCCMS-3.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms

Enabling access to intel context