Central Management System 11.0.0 Release Notes

Prev Next

New features and changes

This section describes new features in Trellix Central Management System release 11.0.0.

  • Support OS Upgrade to AlmaLinux 9.2

    The base platform of Central Management System is upgraded to AlmaLinux 9.2 that provides enhanced stability, security, and performance.

  • Allow users to enable VNC for submissions that were made through a malware repository from Malware Analysis and Central Management System.

  • Alert triage bundles can now be fetched through CMS web service API.

  • CMSHA is now supported in Azure.

  • The 3rd Party Feeds page is now available in Central Management System. Users can now add, view, and download feeds directly from the web interface of both products. Also, new sub-tabs called Allowed Lists and Blocked Lists are added. These help users manage entries by letting them add, view, update, or delete items using criteria such as URL, MD5, SHA256, or Regex URL.

  • The OpenSSL library is upgraded to version 3.1.x to strengthen security, enhance performance, and extend cryptographic functionality.

Resolved issues

The following issues were resolved in the Central Management System 11.0.0 release.

Tracking number

Summary

CMS-17093

Redirection from the eAlerts Quarantine page to the eAlert Details page for a single riskware alert now functions as expected.

CMS-17207

Fixes the issue where the Email Quarantine did not display the percentage (%) value when all EX's were selected.

CMS-17220

Fixes the issue where the success message for 'Advanced Rules' disappears in the UI.

COM-31520, COM-31516

Vulnerability Validation for CVE-2023-5869

Resolution for the vulnerability designated as CVE-2023-5869 was implemented in PostgreSQL 14.10 binaries. In the present release, version 11.0.0, PostgreSQL 14.11 is deployed, thereby incorporating the necessary fixes from version 14.10 and effectively mitigating the aforementioned vulnerability.

CMS-32390

Fixes the issue where inconsistent email counts observed after upgrading to version 10.0.1.

CMS-32397

Fixes the issue where notifications are delayed on the Central Management System to the customer SIEM when handling a large volume of SmartVision data.

CMS-32420

Fixes the issue where inbound SSL-related changes were not reflected on the CMS, and the SSL configuration through the CMS is broken.

CMS-32430

Fixes the issue where Smartvision alert reports did not include the LMS hostname.

CMS-32447

The processed email filters are now working as expected after an upgrade.

CMS-32453

Fixes an alert aggregation issue due to missing supported file type on CMS.

CMS-32460

Fixes the issue where the the scheduled report was throwing exception when no EX was connected.

CMS-32481

Fixes the issue where the 3rd Party Feed tab incorrectly displays 'Allowed Lists' and 'Blocked Lists' for managed NX.

CMS-32519

Fixes the issue where the IPS configuration always defaulted to 'All' and did not allow selection of a specific group.

CMS-32527

Fixes the issue where more than 20 whitelist IPs from the NX were not displaying on the Central Management System.

CMS-32598

Fixes the issue where users encountered a 'FATAL: no pg_hba.conf entry for host 127.0.0.1' error in fe_services on the CMS 10.0.4 after upgrading from version 9.1.1 to 10.0.4.

COM-62287

The JAR versions have been updated to the latest to address multiple CVEs.

COM-62386

Fixes the vulnerability issue for CVE-2024-3651.

COM-62717

Fixes discrepancy issues in alert names between the Central Management System WEB UI and the SIEM.

COM-62752

Vulnerability Validation for CVE-2024-10979

The reported vulnerability for CVE-2024-10979 is addressed by removing the plperlu extension reference and dependencies.

COM-62823

In the latest OS version, the 'ping' command response for non-registered hosts has changed from "unknown host" to the more generic "system error" to improve security hardening.

WEBUI-29843

Users can now select the Email Security group on Queued Emails and Processed Emails.

Known issues

The following issues are known in the Central Management System 11.0.0 release.

Tracking number

Summary

CMS-17198

CMS Web UI displays the "IPS policy out of sync" status even when the IPS policy is actually synchronized across NX instances running various releases.

CMS-15046

File transfer from managed appliances fails sometimes when the maximum system limit for concurrent transfers is reached.

CMS-15792

The MVX-correlated IPS alerts are not deleted in the Central Management System appliance after the cleanup.

CMS-17093

The alert hyperlink in a quarantined message for riskware doesn't redirect to the corresponding riskware alert.

CMS-17136

Email Security - Cloud alert URLs from notifications redirect to the dashboard page due to an error encountered while redirecting the alert link.

CMS-17218

The WEBUI does not update the user login count if the user logs in using CLI concurrently.

CMS-17220

The success message for 'Advanced Rules' disappears quickly from the UI.

CMS-17221

The drop-down list of appliances shows a list of non-EX LMSs and non-supported EXs.

CMS-17224

'Delete' is disabled for 'Write to Group' for 'Advanced Rules' tab.

CMS-17283

The CM UI allows the addition of the Riskware file extension to NX.

CMS-32360

The Retroactive Alert badge appears on the Alerts page but is not displayed on the "Malicious Emails" page.

CMS-32390

Inconsistent email counts observed after upgrading to version 10.0.1.

CMS-32410

The 'show guest-images download' CLI incorrectly displays the message "% Error calculating size of partial download." when pushing guest-images to managed EX from the 'Update Sensors' tab.

CMS-32420

Inbound SSL-related changes are not reflected on the CMS, and the SSL configuration through the CMS is broken.

CMS-32481

The '3rd Party Feed' tab displays 'Allowed Lists' and 'Blocked Lists' for managed NX. These two tabs should be disregarded.

CMS-32482

IPS policy sync configurations and sync jobs are not retained after the CMS upgrade; the master policy must be reconfigured post-upgrade.

CMS-32518

The option to add to the whitelist is disabled for both victims and attackers in Network Anomalies.

CMS-32520

Accessing the 'IPS Configure' and 'IPS Custom Rules' pages results in a UI error and a Java-related java.ERR issue, related to the WSAPI, on an integrated NX that was converted from a sensor.

CMS-32557

3rd Party Feed TAXII tab is not available on CM.

CMS-32580

Alert suppression is not functioning correctly when configured through the CMS UI.

CMS-32590

The submission is still marked as a duplicate even after the feed is deleted from CM.

CMS-32594

MD5 and SHA256 feeds added in CMS are both listed as "HASH".

CMS-32596

CMS allows duplicate feed entries when the same feed name is added after it exists on LMS.

CMS-32600

When the 25K feed limit is reached through the Web UI, additional feeds cannot be uploaded through the Web UI.

CMS-32611

Substring search for tag names in Alerts is not functioning as expected.

CMS-32612

LDAP: SSH access for local users does not function as expected according to the 'aaa authorization rules'.

CMS-32627

The CMS UI displays two VNC icons.

CMSHA-1607

The cluster cannot be formed after downgrading from 11.0.0 to 10.0.4.

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

COM-63527

Instead of originating from the designated live interface (ether2), the sandbox analysis traffic is incorrectly originating from the management interface (ether1).

WEBUI-29938

QR Code badge does not appear for detected alert on NX Alerts Tab.

WEBUI-29993

The WebUI becomes unresponsive when the FIREEYE_APPLIANCE license expires.

WEBUI-29994

The sorting functionality for the 'File Name' and 'File Type' columns is not working in Alerts.

WEBUI-30015

Redirection of Malicious URLs and Malicious Attachments from the Dashboard's Alerts Summary page incorrectly navigates to the Recipient tab instead of the Alerts tab on the eAlerts page.

WEBUI-30022

Unable to generate XML report for report type 'URL Counters in Emails Hourly Stats'.

WEBUI-30028

Unable to add/delete/update the IPS custom variable when group selected in All mode.

Upgrade support

The Trellix Central Management System 11.0.0 release requires a reboot for the update to take effect. You can upgrade your CMS appliance to 11.0.0 from release 9.1.0 or later.

Prerequisite for upgrading appliances with SSH-DSA2

Prior to upgrading to CMS version 11.0.0, for all managed appliances by CMS using SSH-DSA2 authentication, perform the following:

  1. Access the CMS web UI and remove the appliance record that is configured with SSH−DSA2 authentication.

  2. Add the appliance back to CMS, ensuring you configure it with SSH−RSA2 authentication.

  3. Proceed with the CMS upgrade.

Note

After an upgrade to version 11.0.0, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Upgrading MVX clusters

Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-11.0.0 release to 11.0.0 is not supported. You must break down the pre-11.0.0 MVX cluster and upgrade the individual VX node through CMS > Appliances > Nodes. Follow the procedure in this Knowledge article to upgrade your MVX clusters.

Known limitation

HA cluster rebuild is required if CMSHA setup is downgraded from version 11.0.0 to 10.0.x or below.

  1. Stop the HA engine on both nodes by executing the following command on each node:

    ha engine stop
  2. Reset the HA cluster configuration on each node:

    ha engine reset cluster-config

    When prompted, type 'YES'.

  3. Rebuild the HA cluster:

    configuration jump-start

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 11.0.0.

Downloading content from the DTI offline update portal

If you download Central Management 11.0.0 security content from the DTI Offline Update Portal, use the SCCMS-3.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

Enabling access to intel context