Central Management System 10.0.4 Release Notes

Prev Next

Note

Release 10.0.4 is the current release after 10.0.2 for Central Management System.

Resolved issues

The following issues were resolved in the Central Management System 10.0.4 release.

Tracking number

Summary

CMS-32471

Fixes the issue that caused delayed notifications in the CMS UI for SIEM users with extensive SmartVision usage.

CMS-32472

Fixes an issue where the monitor graph displayed inconsistently on the NX and CMS Web UI.

COM-31727

To mitigate the Terrapin Vulnerability (CVE-2023-48795), the chacha20 cipher is removed from our high-security list for non-FIPS/non-CC customers using the high-security list. Now, the Trellix platform is not vulnerable to Terrapin Vulnerability (CVE-2023-48795) with default configuration. We plan to upgrade to the latest stable version of OpenSSH in the upcoming 11.0 major release to further harden and resolve the vulnerable option related to the Terrapin Vulnerability.

COM-62557

To further harden the security of our products, we have upgraded Apache HTTPd to version 2.4.62, the latest stable release.

COM-62575

Fixes an issue where the Helix Alert notification was not displayed.

COM-62580

Fixes an issue where the geolocation service is now updated in the appliance.

Known issues

The following issues are known in the Central Management System 10.0.4 release.

Tracking number

Summary

CMS-17198

CMS Web UI displays the "IPS policy out of sync" status even when the IPS policy is actually synchronized across NX instances running various releases.

CMS-17224

'Delete' is disabled for 'Write to Group' for 'Advanced Rules' tab.

CMS-15046

File transfer from managed appliances fails sometimes when the maximum system limit for concurrent transfers is reached.

CMS-15792

The MVX-correlated IPS alerts are not deleted in the Central Management System appliance after the cleanup.

CMS-17093

The alert hyperlink in a quarantined message for riskware doesn't redirect to the corresponding riskware alert.

CMS-17136

Email Security - Cloud alert URLs from notifications redirect to the dashboard page due to an error encountered while redirecting the alert link.

CMS-17207

Email Quarantine does not display percentage values when all EX appliances are selected.

CMS-17218

The WEBUI does not update the user login count if the user logs in using CLI concurrently.

CMS-17220

The success message for 'Advanced Rules' disappears quickly from the UI.

CMS-17221

The drop-down list of appliances shows a list of non-EX LMSs and non-supported EXs.

CMS-32360

The Retroactive Alert badge appears on the Alerts page but is not displayed on the "Malicious Emails" page.

CMS-32390

Inconsistent email counts observed after upgrading to version 10.0.1.

CMS-32410

The 'show guest-images download' CLI incorrectly displays the message "% Error calculating size of partial download." when pushing guest-images to managed EX from the 'Update Sensors' tab.

CMS-32420

Inbound SSL-related changes are not reflected on the CMS, and the SSL configuration through the CMS is broken.

CMS-32481

The '3rd Party Feed' tab displays 'Allowed Lists' and 'Blocked Lists' for managed NX. These two tabs should be disregarded.

CMS-32482

IPS policy sync configurations and sync jobs are not retained after the CMS upgrade; the master policy must be reconfigured post-upgrade.

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

WEBUI-29843

Users are unable to select the Email Security group on Queued Emails and Processed Emails.

Upgrade support

The Trellix Central Management System 10.0.4 release requires a reboot for the update to take effect. You can upgrade your CMS appliance to 10.0.4 from release 9.0.0 or later.

Note

After an upgrade to version 10.0.4, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Upgrading MVX clusters

Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-9.1.0 release to 10.0.4 is not supported. Follow the procedure in this Community article to upgrade your MVX clusters.

Note

To upgrade 9.1.x MVX clusters, you must first upgrade the CMS to version 10.0.2.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.

Downloading content from the DTI offline update portal

If you download Central Management 10.0.4 security content from the DTI Offline Update Portal, use the SCCMS-3.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

Enabling access to intel context