Central Management System 11.0.1 Release Notes

Prev Next

New features

This section describes new features in Trellix Central Management System release 11.0.1.

  • HelixConnect IPv6 compatibility — Enabled full compatibility of HelixConnect with CMS operating in IPv6 mode, allowing reliable connections and data communication over IPv6 networks.

  • Support for DHCPv6 Hostname registration — The Trellix appliance now supports hostname registration with DHCPv6 servers, making the appliance discoverable on the network by its fully qualified domain name (FQDN). This feature ensures reliable connectivity in pure IPv6 environments. Use the following CLI commands to set the hostname and enable the feature:

    ipv6 dhcp hostname <hostname>
    ipv6 dhcp send-hostname true
  • TACACS+ server support for IPv6 — Starting with version 11.0.1, you can now configure TACACS+ servers with IPv6 addresses for Authentication, Authorization, and Accounting (AAA) services. This enhancement expands our IPv6 support and provides greater flexibility in configuring authentication servers in your network environment.

  • To align with CA/B forum standards, the Organization Unit (OU) field in certificates and CSRs is now configurable. The field is disabled by default on new installations but remains enabled by default on upgraded systems to maintain compatibility with internal CAs. You can disable this using the new [no] crypto certificate generation default include-deprecated org-unit enable CLI command.

  • The configuration jumpstart command now supports both pure IPv6 and dual-stack (IPv4/IPv6) configurations, enabling successful deployment in IPv6-only environments.

  • Organizational Unit field CLIs

    • crypto certificate generation default include-deprecated org-unit enable — This CLI will enable the Organizational Unit for the CSR certificate. With the "Organizational Unit" enabled, the CSR/certificate generated on the appliance will include the "Organizational Unit".

    • [no] crypto certificate generation default include-deprecated org-unit enable — This CLI will disable the Organizational Unit for the CSR certificate. With the "Organizational Unit" disabled, the CSR/certificate generated on the appliance will NOT include the "Organizational Unit".

  • Users can now download emails categorized as Clean from the 'Processed Emails' web UI page in CMS using the Download option.

  • Introduced a View Email option on the 'Processed Emails' web UI page in EX and CMS, enabling users to open and review clean (non-quarantined) emails directly from the console.

Enhancements

  • Enhanced SAML support for High Availability (HA) environments — To prevent SAML authentication failures after a High Availability (HA) failover, you can now configure node-specific SAML FQDNs. This enhancement allows the primary and secondary nodes to maintain unique FQDNs by excluding the SAML configuration from database synchronization.

  • CMSHA now supports IPv6 for High Availability — Support for IPv6 has been added to the CMSHA (High Availability) cluster engine. Users can now configure HA clusters in environments using IPv6-only, IPv4-only, or dual-stack (both IPv4 and IPv6) addressing. This enhancement updates both the core clustering mechanism and the initial configuration wizard to fully support IPv6.

  • Web UI support to release Quarantined emails by MD5 or URL — CMS web UI now provides an option to release quarantined emails using a URL or MD5 hash, significantly improving incident response workflow.

  • The appliance base components have been upgraded to fully support TLS 1.3 for management protocols, including the Web management interface. This enhancement enforces access rules when Web Client Certificate Authentication is enabled, client certificates are now required for all WSAPI calls, and there is no fallback to other authentication methods for Web Portal access.

  • Users can no longer upload files using the file log-archive command.

Resolved issues

The following issues were resolved in the Central Management System 11.0.1 release.

Tracking number

Summary

COM-62386

Fixes the issue where the appliance included a version of the python3 idna software module associated with CVE-2024-3651. The module is now updated to a non-vulnerable version. This proactively addresses the potential vulnerability even though the appliance did not use the specific vulnerable function.

COM-63130

Removed the diffie-hellman-group14-sha1 Key Exchange (KEX) cipher from our supported CC and FIPS cipher lists.

COM-63373

Fixed CVE-2022-27406 vulnerability by updating the FreeType library.

COM-63390

Resolved an issue that caused login connections from CMS to other appliances to immediately disconnect after upgrading to version 11.0.0.

COM-63415

Resolved an issue where logs were not being sent to Splunk after upgrading to version 11, particularly when the use-fenet-proxy option was disabled.

COM-63502

Fixed the autocomplete issue where the autocomplete function is disabled on all password fields to prevent browsers from automatically saving and filling in sensitive data.

COM-63513

Resolved an issue where an error response during login attempts exposed an internal system path.

COM-63528

Resolved an issue where the AX appliance's management interface (ether1) was incorrectly attempting to establish connections for sandbox analysis.

COM-63549

Resolved an issue that prevented users from logging in to the PKI/CAC server after upgrading to version 11.0.0.

CMS-17198

Fixed the issue where CMS Web UI displays the "IPS policy out of sync" status even when the IPS policy is actually synchronized across NX instances running various releases.

CMS-17093

The alert hyperlink in a quarantined message for riskware now redirects to the corresponding riskware alert.

CMS-17221

Fixed the issue where the drop-down list of appliances shows a list of non-EX LMSs and non-supported EXs.

CMS-32390

Correct number of email counts are now displayed after upgrading to version 10.0.1.

CMS-32520

Fixed the issue where accessing the 'IPS Configure' and 'IPS Custom Rules' pages resulted in a UI error and a Java-related java.ERR issue, related to the WSAPI, on an integrated NX that was converted from a sensor.

CMS-32596

CMS does not allow duplicate feed entries when the same feed name is added after it exists on LMS.

CMS-32611

Substring search for tag names in Alerts is now functioning as expected.

CMS-32627

Fixed the issue where the CMS UI displayed two VNC icons.

WEBUI-29938

QR Code badge appears correctly for detected alert on NX Alerts Tab.

WEBUI-30013

Addresses remote code execution vulnerability in the web UI. An attacker could exploit this vulnerability to execute commands on the underlying operating system by viewing malware artifact details in the Alerts view.

WEBUI-30015

Redirection of Malicious URLs and Malicious Attachments from the Dashboard's Alerts Summary page now navigates correctly to the Recipient tab instead of the Alerts tab on the eAlerts page.

WEBUI-30022

The system now generates an XML report for report type 'URL Counters in Emails Hourly Stats'.

Known issues

The following issues are known in the Central Management System 11.0.1 release.

Tracking number

Summary

CMS-15046

File transfer from managed appliances fails sometimes when the maximum system limit for concurrent transfers is reached.

CMS-17136

Email Security - Cloud alert URLs from notifications redirect to the dashboard page due to an error encountered while redirecting the alert link.

CMS-17218

The WEBUI does not update the user login count if the user logs in using CLI concurrently.

CMS-17224

'Delete' is disabled for 'Write to Group' for 'Advanced Rules' tab.

CMS-17283

The CM UI allows the addition of the Riskware file extension to NX.

CMS-32360

The Retroactive Alert badge appears on the Alerts page but is not displayed on the "Malicious Emails" page.

CMS-32410

The 'show guest-images download' CLI incorrectly displays the message "% Error calculating size of partial download." when pushing guest-images to managed EX from the 'Update Sensors' tab.

CMS-32482

IPS policy sync configurations and sync jobs are not retained after the CMS upgrade; the master policy must be reconfigured post-upgrade.

CMS-32518

The option to add to the whitelist is disabled for both victims and attackers in Network Anomalies.

CMS-32557

3rd Party Feed TAXII tab is not available on CM.

CMS-32580

Alert suppression is not functioning correctly when configured through the CMS UI.

CMS-32590

The submission is still marked as a duplicate even after the feed is deleted from CM.

CMS-32594

MD5 and SHA256 feeds added in CMS are both listed as "HASH".

CMS-32600

When the 25K feed limit is reached through the Web UI, additional feeds cannot be uploaded through the Web UI.

CMS-32612

LDAP: SSH access for local users does not function as expected according to the 'aaa authorization rules'.

CMS-32664

PE artifact on CMS does not show data on Alerts view.

CMS-32685

When uploading a duplicate feed using the Override option with an invalid feed file in Managed EX, the existing feed status is incorrectly updated to empty or “Validation Failed”.

CMS-32726

The master policy name displays incorrectly on the IPS sync configuration page.

CMS-32757

The NX/EX Alerts page does not display correctly on CMS systems that were originally remanufactured with OS version 8.7.x or earlier.

CMSHA-1622

Root user authentication fails with pam_unix errors after upgrading to version 11 in CMS High Availability (HA) environments.

CMSHA-1633

When High Availability (HA) is deployed using IPv4 and later switched to IPv6, users may face difficulty reconfiguring the cluster back to IPv4 HA.

COM-30656

Negation symbol '!' is not working before the hostname or the username in deny user list.

COM-63204

Setting the IPMI password is currently restricted to a maximum length of 16 characters.

COM-63635

Compliance mode appliances are logging too much noise with SSL_ERROR_WANT_READ informational status.

WEBUI-29994

The sorting functionality for the 'File Name' and 'File Type' columns is not working in Alerts.

Additional information

Upgrade support

The Trellix Central Management System 11.0.1 release requires a reboot for the update to take effect. You can upgrade your CMS appliance to 11.0.1 from release 9.1.x or later.

Important

When upgrading an X500 CMS running in FIPS/CC compliance mode to version 11.0.1, you must reapply the compliance mode immediately after the upgrade. Use the CLI command compliance apply standard <standard name> and save the configuration using the CLI write memory.

After reapplying compliance mode, ensure that any necessary compliance options overrides are reasserted as needed. In rare instances, the appliance may become unresponsive before compliance can be applied. If this occurs, the appliance may need to be power cycled.

For CMSHA in compliance mode, the cluster engine may intermittently enter a "stopped" state on some systems after the upgrade. In such cases, execute "ha engine restart" to restart the HA cluster.

Important

If your CMS was initially remanufactured with OS version 8.7.x or earlier, the NX/EX Alerts page may not display correctly after upgrading to release 11.0.1. If you encounter this issue, apply the required hotfix using the following CLI commands:

hostname (config) # image hotfix fetch scp://eng-hotfix:VsXVQug8FVOCNq7a@supportrepo.fireeye.com/home/eng-hotfix/DC4Cuic/image-CMS-32757_CMS11.0.1-fehfx.img
hostname (config) # image hotfix install image-CMS-32757_CMS11.0.1-fehfx.img

Upgrading MVX clusters

Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-9.1.0 release to 11.0.1 is not supported. See the Upgrading IVX Clusters to Version 11.0 section for more information.

Note

You cannot upgrade clusters directly from versions 9.1.x or 10.0.x to 11.0.1. To upgrade, you must first dismantle the cluster and then upgrade each IVX standalone node individually to version 11.0.1.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 11.0.1.