New features
This section describes new features in Trellix Central Management System release 11.0.1.
HelixConnect IPv6 compatibility — Enabled full compatibility of HelixConnect with CMS operating in IPv6 mode, allowing reliable connections and data communication over IPv6 networks.
Support for DHCPv6 Hostname registration — The Trellix appliance now supports hostname registration with DHCPv6 servers, making the appliance discoverable on the network by its fully qualified domain name (FQDN). This feature ensures reliable connectivity in pure IPv6 environments. Use the following CLI commands to set the hostname and enable the feature:
ipv6 dhcp hostname <hostname> ipv6 dhcp send-hostname trueTACACS+ server support for IPv6 — Starting with version 11.0.1, you can now configure TACACS+ servers with IPv6 addresses for Authentication, Authorization, and Accounting (AAA) services. This enhancement expands our IPv6 support and provides greater flexibility in configuring authentication servers in your network environment.
To align with CA/B forum standards, the (OU) field in certificates and CSRs is now configurable. The field is disabled by default on new installations but remains enabled by default on upgraded systems to maintain compatibility with internal CAs. You can disable this using the new [no] crypto certificate generation default include-deprecated org-unit enable CLI command.
The configuration jumpstart command now supports both pure IPv6 and dual-stack (IPv4/IPv6) configurations, enabling successful deployment in IPv6-only environments.
field CLIs
crypto certificate generation default include-deprecated org-unit enable — This CLI will enable the Organizational Unit for the CSR certificate. With the "Organizational Unit" enabled, the CSR/certificate generated on the appliance will include the "Organizational Unit".
[no] crypto certificate generation default include-deprecated org-unit enable — This CLI will disable the Organizational Unit for the CSR certificate. With the "Organizational Unit" disabled, the CSR/certificate generated on the appliance will NOT include the "Organizational Unit".
Users can now download emails categorized as Clean from the 'Processed Emails' web UI page in CMS using the Download option.
Introduced a View Email option on the 'Processed Emails' web UI page in EX and CMS, enabling users to open and review clean (non-quarantined) emails directly from the console.
Enhancements
Enhanced SAML support for High Availability (HA) environments — To prevent SAML authentication failures after a High Availability (HA) failover, you can now configure node-specific SAML FQDNs. This enhancement allows the primary and secondary nodes to maintain unique FQDNs by excluding the SAML configuration from database synchronization.
CMSHA now supports IPv6 for High Availability — Support for IPv6 has been added to the CMSHA (High Availability) cluster engine. Users can now configure HA clusters in environments using IPv6-only, IPv4-only, or dual-stack (both IPv4 and IPv6) addressing. This enhancement updates both the core clustering mechanism and the initial configuration wizard to fully support IPv6.
Web UI support to release Quarantined emails by MD5 or URL — CMS web UI now provides an option to release quarantined emails using a URL or MD5 hash, significantly improving incident response workflow.
The appliance base components have been upgraded to fully support TLS 1.3 for management protocols, including the Web management interface. This enhancement enforces access rules when Web Client Certificate Authentication is enabled, client certificates are now required for all WSAPI calls, and there is no fallback to other authentication methods for Web Portal access.
Users can no longer upload files using the file log-archive command.
Resolved issues
The following issues were resolved in the Central Management System 11.0.1 release.
Tracking number | Summary |
|---|---|
COM-62386 | Fixes the issue where the appliance included a version of the python3 idna software module associated with CVE-2024-3651. The module is now updated to a non-vulnerable version. This proactively addresses the potential vulnerability even though the appliance did not use the specific vulnerable function. |
COM-63130 | Removed the diffie-hellman-group14-sha1 Key Exchange (KEX) cipher from our supported CC and FIPS cipher lists. |
COM-63373 | Fixed CVE-2022-27406 vulnerability by updating the FreeType library. |
COM-63390 | Resolved an issue that caused login connections from CMS to other appliances to immediately disconnect after upgrading to version 11.0.0. |
COM-63415 | Resolved an issue where logs were not being sent to Splunk after upgrading to version 11, particularly when the use-fenet-proxy option was disabled. |
COM-63502 | Fixed the autocomplete issue where the autocomplete function is disabled on all password fields to prevent browsers from automatically saving and filling in sensitive data. |
COM-63513 | Resolved an issue where an error response during login attempts exposed an internal system path. |
COM-63528 | Resolved an issue where the AX appliance's management interface (ether1) was incorrectly attempting to establish connections for sandbox analysis. |
COM-63549 | Resolved an issue that prevented users from logging in to the PKI/CAC server after upgrading to version 11.0.0. |
CMS-17198 | Fixed the issue where CMS Web UI displays the "IPS policy out of sync" status even when the IPS policy is actually synchronized across NX instances running various releases. |
CMS-17093 | The alert hyperlink in a quarantined message for riskware now redirects to the corresponding riskware alert. |
CMS-17221 | Fixed the issue where the drop-down list of appliances shows a list of non-EX LMSs and non-supported EXs. |
CMS-32390 | Correct number of email counts are now displayed after upgrading to version 10.0.1. |
CMS-32520 | Fixed the issue where accessing the 'IPS Configure' and 'IPS Custom Rules' pages resulted in a UI error and a Java-related java.ERR issue, related to the WSAPI, on an integrated NX that was converted from a sensor. |
CMS-32596 | CMS does not allow duplicate feed entries when the same feed name is added after it exists on LMS. |
CMS-32611 | Substring search for tag names in Alerts is now functioning as expected. |
CMS-32627 | Fixed the issue where the CMS UI displayed two VNC icons. |
WEBUI-29938 | QR Code badge appears correctly for detected alert on NX Alerts Tab. |
WEBUI-30013 | Addresses remote code execution vulnerability in the web UI. An attacker could exploit this vulnerability to execute commands on the underlying operating system by viewing malware artifact details in the Alerts view. |
WEBUI-30015 | Redirection of Malicious URLs and Malicious Attachments from the Dashboard's Alerts Summary page now navigates correctly to the Recipient tab instead of the Alerts tab on the eAlerts page. |
WEBUI-30022 | The system now generates an XML report for report type 'URL Counters in Emails Hourly Stats'. |
Known issues
The following issues are known in the Central Management System 11.0.1 release.
Tracking number | Summary |
|---|---|
CMS-15046 | File transfer from managed appliances fails sometimes when the maximum system limit for concurrent transfers is reached. |
CMS-17136 | Email Security - Cloud alert URLs from notifications redirect to the dashboard page due to an error encountered while redirecting the alert link. |
CMS-17218 | The WEBUI does not update the user login count if the user logs in using CLI concurrently. |
CMS-17224 | 'Delete' is disabled for 'Write to Group' for 'Advanced Rules' tab. |
CMS-17283 | The CM UI allows the addition of the Riskware file extension to NX. |
CMS-32360 | The Retroactive Alert badge appears on the Alerts page but is not displayed on the "Malicious Emails" page. |
CMS-32410 | The 'show guest-images download' CLI incorrectly displays the message "% Error calculating size of partial download." when pushing guest-images to managed EX from the 'Update Sensors' tab. |
CMS-32482 | IPS policy sync configurations and sync jobs are not retained after the CMS upgrade; the master policy must be reconfigured post-upgrade. |
CMS-32518 | The option to add to the whitelist is disabled for both victims and attackers in Network Anomalies. |
CMS-32557 | 3rd Party Feed TAXII tab is not available on CM. |
CMS-32580 | Alert suppression is not functioning correctly when configured through the CMS UI. |
CMS-32590 | The submission is still marked as a duplicate even after the feed is deleted from CM. |
CMS-32594 | MD5 and SHA256 feeds added in CMS are both listed as "HASH". |
CMS-32600 | When the 25K feed limit is reached through the Web UI, additional feeds cannot be uploaded through the Web UI. |
CMS-32612 | LDAP: SSH access for local users does not function as expected according to the 'aaa authorization rules'. |
CMS-32664 | PE artifact on CMS does not show data on view. |
CMS-32685 | When uploading a duplicate feed using the option with an invalid feed file in Managed EX, the existing feed status is incorrectly updated to empty or “Validation Failed”. |
CMS-32726 | The master policy name displays incorrectly on the IPS sync configuration page. |
CMS-32757 | The NX/EX Alerts page does not display correctly on CMS systems that were originally remanufactured with OS version 8.7.x or earlier. |
CMSHA-1622 | Root user authentication fails with pam_unix errors after upgrading to version 11 in CMS High Availability (HA) environments. |
CMSHA-1633 | When High Availability (HA) is deployed using IPv4 and later switched to IPv6, users may face difficulty reconfiguring the cluster back to IPv4 HA. |
COM-30656 | Negation symbol '!' is not working before the hostname or the username in deny user list. |
COM-63204 | Setting the IPMI password is currently restricted to a maximum length of 16 characters. |
COM-63635 | Compliance mode appliances are logging too much noise with SSL_ERROR_WANT_READ informational status. |
WEBUI-29994 | The sorting functionality for the 'File Name' and 'File Type' columns is not working in Alerts. |
Additional information
Upgrade support
The Trellix Central Management System 11.0.1 release requires a reboot for the update to take effect. You can upgrade your CMS appliance to 11.0.1 from release 9.1.x or later.
Important
When upgrading an X500 CMS running in FIPS/CC compliance mode to version 11.0.1, you must reapply the compliance mode immediately after the upgrade. Use the CLI command compliance apply standard <standard name> and save the configuration using the CLI write memory.
After reapplying compliance mode, ensure that any necessary compliance options overrides are reasserted as needed. In rare instances, the appliance may become unresponsive before compliance can be applied. If this occurs, the appliance may need to be power cycled.
For CMSHA in compliance mode, the cluster engine may intermittently enter a "stopped" state on some systems after the upgrade. In such cases, execute "ha engine restart" to restart the HA cluster.
Important
If your CMS was initially remanufactured with OS version 8.7.x or earlier, the NX/EX Alerts page may not display correctly after upgrading to release 11.0.1. If you encounter this issue, apply the required hotfix using the following CLI commands:
hostname (config) # image hotfix fetch scp://eng-hotfix:VsXVQug8FVOCNq7a@supportrepo.fireeye.com/home/eng-hotfix/DC4Cuic/image-CMS-32757_CMS11.0.1-fehfx.img
hostname (config) # image hotfix install image-CMS-32757_CMS11.0.1-fehfx.imgUpgrading MVX clusters
Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-9.1.0 release to 11.0.1 is not supported. See the Upgrading IVX Clusters to Version 11.0 section for more information.
Note
You cannot upgrade clusters directly from versions 9.1.x or 10.0.x to 11.0.1. To upgrade, you must first dismantle the cluster and then upgrade each IVX standalone node individually to version 11.0.1.
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 11.0.1.