File Protect 9.0.1 Release Notes

Prev Next

2020 / Software Release 9.0.1 / Revision

Announcements

This document provides an overview of the resolved issues and known issues in the FireEye File Protect 9.0.1 release.

Customer Security Best Practices

Because our quality assurance process includes continuous security testing, FireEye recommends updating all FireEye products with the latest releases as soon as possible. As an overall strategy to reduce risk exposure, customers are also encouraged to follow best practices, which include:

  • Always keep the product version up-to-date

  • Limit network access to the management interfaces of the appliance using firewalls or similar measures

  • Only issue accounts to trusted administrators

  • Use strong passwords

  • Monitor logs

  • Restrict physical access to the appliance to trusted administrators

Upgrade

The FireEye File Protect 9.0.1 release requires a reboot for the update to take effect. You can upgrade your File Protect appliance to 9.0.1 from release 8.2.0 or later.

To upgrade your File Protect appliance to 9.0.1 from a Central Management (CM Series) appliance, the Central Management appliance must be running the 9.0.1 release or later.

Blue circular icon with a clipboard inside

NOTE: After an upgrade to version 9.0.1, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected.

Blue circular icon with a clipboard inside

NOTE: After an upgrade to version 9.0.1, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.

Downloading Content from the DTI Offline Update Portal

If you download File Protect 9.0.1 security content from the DTI Offline Update Portal, use the SCNET-6.0 channel of the portal.

Red circular warning icon with white exclamation mark

CAUTION! Downloading security content from a different channel will result in a loss of detection.

    For details, see the FireEye DTI Offline Update Portal User Guide.



YARA Rules Supported Versions

    YARA rules support version 3.11.0.

Blue circular information icon with white exclamation

IMPORTANT: Before you upgrade an File Protect appliance to the 9.0.1 release, modify any custom YARA rules to YARA 3.11.0. For details about YARA 3.11.0, see yara Documentation, Release 3.11.0 by Victor Alvarez.

Enabling Access to Intel Context

    Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The FireEye Research Labs team continually uploads the latest threat intelligence to the FireEye Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.

    Appliances now need access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location. To determine the IP addresses for your location, go to https://dnschecker.org/#A/context.fireeye.com. See the AWS IP address range documentation for information about whitelisting the IP addresses.



Fixed File Protect Issues

The following issues were resolved in the File Protect 9.0.1 Release.

A blue circular clipboard icon indicating a note.

NOTE: The relevant issue tracking numbers for each item are included in parentheses.

  • Any File Protect hardware appliance, when operating with its MVX engine enabled, posed a potential security risk if a virtual guest operating system (a “guest image”) used certain Intel® processors. This vulnerability could allow an authenticated user to enable denial of service of the host system through local access. This issue has been resolved. (COM-26768)

  • The use of some Open Source password security auditing and password recovery tools caused the File Protect appliance CPU usage to spike to 100%, which could cause network latency. This issue has been resolved. (COM-27701)

  • FX 5400 and FX 8400 appliances failed to come up after a system reload. This issue has been resolved. (COM-27757)

  • A File Protect appliance managed by an offline Central Management appliance could not be upgraded. This issue has been resolved. (COM-27824)

  • In the File Protect appliance alert notification logs and “Service Health Statistics Trend” dashboard widget, the “URL Transform” service status was shown to be alternately Degraded then Healthy. This issue has been resolved. (EMPS-15017)

  • On virtual File Protect appliances running Release 9.0.0, the CLI incorrectly included the guest-images download-and-install command. This issue has been resolved. (FMPS-2243, COM-27903)

  • A scan job could remain stuck in the Aborted state for varying periods of time. This issue has been resolved. (FMPS-1970, FMPS-2132)

  • On File Protect appliances running Release 9.0.0, the show pm process scsd command shows that the SCSD process remains in “pending” state if the appliance was not in a Helix deployment. This issue has been resolved. (FMPS-2203)

  • After a File Protect appliance was upgraded to Release 9.0.0, analyzed files were no longer moved out of the incoming folder as configured. As a result, in the case of a continuous scan, analyzed files were scanned repeatedly. This issue has been resolved. (FMPS-2224)

© 2020 FireEye

Release 9.0.1

Fixed File Protect Issues


  • On virtual File Protect appliances running Release 9.0.0, the Summary view of the About tab incorrectly displayed the “Guest Images” card. This issue has been resolved. (FMPS-2240)

  • SharePoint shares on the File Protect could not be deleted using either the Web UI or CLI. This issue has been resolved. (FMPS-2245, FMPS-2170)

  • After a File Protect appliance was upgraded to release 9.0.0, the “Files Analyzed By Storages” dashboard widget was blank. This issue has been resolved. (FMPS-2247)

  • On a File Protect appliance, 0 byte length files and large-sized (above the configured size) files were not moved from the source share to the directory for Unknown files after scanning. This issue has been resolved. (FMPS-2260)



Known File Protect Issues

The following issues are known in File Protect release 9.0.1.

Blue circular clipboard icon

NOTE: The relevant issue tracking numbers for each item are included in parentheses.

  • Occasionally the File Protect appliance does not update the “Total Files” value for a continuous scan job. This results in the Scans page reporting a percentage complete number exceeding 100% in the “Status and Actions” column. (FMPS-2256)

  • After an upgrade to version 9.0.0, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected. (WEBUI-13417)