New features and changes
This section describes new features in Trellix Central Management System release 11.0.0.
Support OS Upgrade to AlmaLinux 9.2
The base platform of Central Management System is upgraded to AlmaLinux 9.2 that provides enhanced stability, security, and performance.
Allow users to enable VNC for submissions that were made through a malware repository from Malware Analysis and Central Management System.
Alert triage bundles can now be fetched through CMS web service API.
CMSHA is now supported in Azure.
The 3rd Party Feeds page is now available in Central Management System. Users can now add, view, and download feeds directly from the web interface of both products. Also, new sub-tabs called Allowed Lists and Blocked Lists are added. These help users manage entries by letting them add, view, update, or delete items using criteria such as URL, MD5, SHA256, or Regex URL.
The OpenSSL library is upgraded to version 3.1.x to strengthen security, enhance performance, and extend cryptographic functionality.
Resolved issues
The following issues were resolved in the Central Management System 11.0.0 release.
Tracking number | Summary |
|---|---|
CMS-17093 | Redirection from the eAlerts Quarantine page to the eAlert Details page for a single riskware alert now functions as expected. |
CMS-17207 | Fixes the issue where the Email Quarantine did not display the percentage (%) value when all EX's were selected. |
CMS-17220 | Fixes the issue where the success message for 'Advanced Rules' disappears in the UI. |
COM-31520, COM-31516 | Vulnerability Validation for CVE-2023-5869 Resolution for the vulnerability designated as CVE-2023-5869 was implemented in PostgreSQL 14.10 binaries. In the present release, version 11.0.0, PostgreSQL 14.11 is deployed, thereby incorporating the necessary fixes from version 14.10 and effectively mitigating the aforementioned vulnerability. |
CMS-32390 | Fixes the issue where inconsistent email counts observed after upgrading to version 10.0.1. |
CMS-32397 | Fixes the issue where notifications are delayed on the Central Management System to the customer SIEM when handling a large volume of SmartVision data. |
CMS-32420 | Fixes the issue where inbound SSL-related changes were not reflected on the CMS, and the SSL configuration through the CMS is broken. |
CMS-32430 | Fixes the issue where Smartvision alert reports did not include the LMS hostname. |
CMS-32447 | The processed email filters are now working as expected after an upgrade. |
CMS-32453 | Fixes an alert aggregation issue due to missing supported file type on CMS. |
CMS-32460 | Fixes the issue where the the scheduled report was throwing exception when no EX was connected. |
CMS-32481 | Fixes the issue where the 3rd Party Feed tab incorrectly displays 'Allowed Lists' and 'Blocked Lists' for managed NX. |
CMS-32519 | Fixes the issue where the IPS configuration always defaulted to 'All' and did not allow selection of a specific group. |
CMS-32527 | Fixes the issue where more than 20 whitelist IPs from the NX were not displaying on the Central Management System. |
CMS-32598 | Fixes the issue where users encountered a 'FATAL: no pg_hba.conf entry for host 127.0.0.1' error in fe_services on the CMS 10.0.4 after upgrading from version 9.1.1 to 10.0.4. |
COM-62287 | The JAR versions have been updated to the latest to address multiple CVEs. |
COM-62386 | Fixes the vulnerability issue for CVE-2024-3651. |
COM-62717 | Fixes discrepancy issues in alert names between the Central Management System WEB UI and the SIEM. |
COM-62752 | Vulnerability Validation for CVE-2024-10979 The reported vulnerability for CVE-2024-10979 is addressed by removing the plperlu extension reference and dependencies. |
COM-62823 | In the latest OS version, the 'ping' command response for non-registered hosts has changed from "unknown host" to the more generic "system error" to improve security hardening. |
WEBUI-29843 | Users can now select the Email Security group on Queued Emails and Processed Emails. |
Known issues
The following issues are known in the Central Management System 11.0.0 release.
Tracking number | Summary |
|---|---|
CMS-17198 | CMS Web UI displays the "IPS policy out of sync" status even when the IPS policy is actually synchronized across NX instances running various releases. |
CMS-15046 | File transfer from managed appliances fails sometimes when the maximum system limit for concurrent transfers is reached. |
CMS-15792 | The MVX-correlated IPS alerts are not deleted in the Central Management System appliance after the cleanup. |
CMS-17093 | The alert hyperlink in a quarantined message for riskware doesn't redirect to the corresponding riskware alert. |
CMS-17136 | Email Security - Cloud alert URLs from notifications redirect to the dashboard page due to an error encountered while redirecting the alert link. |
CMS-17218 | The WEBUI does not update the user login count if the user logs in using CLI concurrently. |
CMS-17220 | The success message for 'Advanced Rules' disappears quickly from the UI. |
CMS-17221 | The drop-down list of appliances shows a list of non-EX LMSs and non-supported EXs. |
CMS-17224 | 'Delete' is disabled for 'Write to Group' for 'Advanced Rules' tab. |
CMS-17283 | The CM UI allows the addition of the Riskware file extension to NX. |
CMS-32360 | The Retroactive Alert badge appears on the Alerts page but is not displayed on the "Malicious Emails" page. |
CMS-32390 | Inconsistent email counts observed after upgrading to version 10.0.1. |
CMS-32410 | The 'show guest-images download' CLI incorrectly displays the message "% Error calculating size of partial download." when pushing guest-images to managed EX from the 'Update Sensors' tab. |
CMS-32420 | Inbound SSL-related changes are not reflected on the CMS, and the SSL configuration through the CMS is broken. |
CMS-32481 | The '3rd Party Feed' tab displays 'Allowed Lists' and 'Blocked Lists' for managed NX. These two tabs should be disregarded. |
CMS-32482 | IPS policy sync configurations and sync jobs are not retained after the CMS upgrade; the master policy must be reconfigured post-upgrade. |
CMS-32518 | The option to add to the whitelist is disabled for both victims and attackers in Network Anomalies. |
CMS-32520 | Accessing the 'IPS Configure' and 'IPS Custom Rules' pages results in a UI error and a Java-related java.ERR issue, related to the WSAPI, on an integrated NX that was converted from a sensor. |
CMS-32557 | 3rd Party Feed TAXII tab is not available on CM. |
CMS-32580 | Alert suppression is not functioning correctly when configured through the CMS UI. |
CMS-32590 | The submission is still marked as a duplicate even after the feed is deleted from CM. |
CMS-32594 | MD5 and SHA256 feeds added in CMS are both listed as "HASH". |
CMS-32596 | CMS allows duplicate feed entries when the same feed name is added after it exists on LMS. |
CMS-32600 | When the 25K feed limit is reached through the Web UI, additional feeds cannot be uploaded through the Web UI. |
CMS-32611 | Substring search for tag names in Alerts is not functioning as expected. |
CMS-32612 | LDAP: SSH access for local users does not function as expected according to the 'aaa authorization rules'. |
CMS-32627 | The CMS UI displays two VNC icons. |
CMSHA-1607 | The cluster cannot be formed after downgrading from 11.0.0 to 10.0.4. |
COM-30656 | Negation symbol '!' is not working before the hostname or the username in deny user list. |
COM-63527 | Instead of originating from the designated live interface (ether2), the sandbox analysis traffic is incorrectly originating from the management interface (ether1). |
WEBUI-29938 | QR Code badge does not appear for detected alert on NX Alerts Tab. |
WEBUI-29993 | The WebUI becomes unresponsive when the FIREEYE_APPLIANCE license expires. |
WEBUI-29994 | The sorting functionality for the 'File Name' and 'File Type' columns is not working in Alerts. |
WEBUI-30015 | Redirection of Malicious URLs and Malicious Attachments from the Dashboard's Alerts Summary page incorrectly navigates to the Recipient tab instead of the Alerts tab on the eAlerts page. |
WEBUI-30022 | Unable to generate XML report for report type 'URL Counters in Emails Hourly Stats'. |
WEBUI-30028 | Unable to add/delete/update the IPS custom variable when group selected in All mode. |
Upgrade support
The Trellix Central Management System 11.0.0 release requires a reboot for the update to take effect. You can upgrade your CMS appliance to 11.0.0 from release 9.1.0 or later.
Prerequisite for upgrading appliances with SSH-DSA2
Prior to upgrading to CMS version 11.0.0, for all managed appliances by CMS using SSH-DSA2 authentication, perform the following:
Access the CMS web UI and remove the appliance record that is configured with SSH−DSA2 authentication.
Add the appliance back to CMS, ensuring you configure it with SSH−RSA2 authentication.
Proceed with the CMS upgrade.
Note
After an upgrade to version 11.0.0, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Upgrading MVX clusters
Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-11.0.0 release to 11.0.0 is not supported. You must break down the pre-11.0.0 MVX cluster and upgrade the individual VX node through CMS > Appliances > Nodes. Follow the procedure in this Knowledge article to upgrade your MVX clusters.
Known limitation
HA cluster rebuild is required if CMSHA setup is downgraded from version 11.0.0 to 10.0.x or below.
Stop the HA engine on both nodes by executing the following command on each node:
ha engine stopReset the HA cluster configuration on each node:
ha engine reset cluster-configWhen prompted, type 'YES'.
Rebuild the HA cluster:
configuration jump-start
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 11.0.0.
Downloading content from the DTI offline update portal
If you download Central Management 11.0.0 security content from the DTI Offline Update Portal, use the SCCMS-3.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the Trellix DTI Offline Update Portal User Guide.