Last Updated: September 17, 2023
Announcements
This document provides an overview of the new features and changes in the Trellix File Protect 9.1.4 release, including any new commands, resolved issues, and known issues.
Every update release is cumulative and includes all features and fixes from the previous release. The Trellix quality assurance process includes continuous security testing. Trellix recommends updating all products with the latest release as soon as possible.
Product compatibility
This Trellix File Protect release supports Central Management appliance.
Upgrade support
The Trellix File Protect 9.1.4 release requires a reboot for the update to take effect. You can upgrade your File Protect appliance to 9.1.4 from release 8.3.0 or later.
To upgrade your File Protect appliance to 9.1.4 from a Central Management (CM Series) appliance, the Central Management appliance must be running the 9.1.4 release or later.
After an upgrade to version 9.1.4, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.
After an upgrade to version 9.1.4, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected.
Note
After an upgrade to version 9.1.4, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 9.1.4.
Downloading content from the DTI offline update portal
If you download File Protect 9.1.4 security content from the DTI Offline Update Portal, use the SCNET-7.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the Trellix DTI Offline Update Portal User Guide.
YARA rules supported versions
YARA rules support version 4.1.0.
Important
Before you upgrade an File Protect appliance to the 9.1.4 release, modify any custom YARA rules to YARA 4.1.0. For details about YARA 4.1.0, see YARA's Documentation, Release 4.1.0 by Victor Alvarez.
Enabling access to intel context
Advanced Threat Intelligence (ATI) is a cloud-based data collection and threat intelligence distribution feature that provides actionable information about MVX-verified events on appliances. The threat intelligence tells you who is the threat actor behind an attack, what has been targeted or breached, and (if known) how to mitigate the threat. The Trellix Research Labs team continually uploads the latest threat intelligence to the Trellix Dynamic Threat Intelligence (DTI) cloud. When an MVX-verified event triggers an alert, the appliance queries the DTI server for threat intelligence and stores the additional information in its database. When you display an ATI alert, the alert details include the threat intelligence.
Appliances now need access to the Amazon Web Services (AWS) cloud for ATI communication. The intel context service is hosted in multiple AWS regions and resolves to multiple IP addresses based on geographic location. To determine the IP addresses for your location, go to https://dnschecker.org. See the AWS IP address range documentation for information about adding the IP addresses to the allow list.
Resolved issues
The following issues were resolved in the File Protect 9.1.4 release.
Tracking number | Summary |
|---|---|
COM-30297 | On the File Protect appliance, the file download action could not download multiple files simultaneously. This issue has been resolved. |
COM-30235 | SMTP alerts using TLS failed to authenticate if the password contained the symbol #. This issue has been resolved. |
COM-30449 | SAML Response decoding failures with IDP have been fixed. The FX appliance displayed a "bad encoding" error when the system's IDP response contained carriage return and newline characters. This issue has been resolved. |
COM-30362 | An HTTPS configuration certificate (ECDSA certificate) could not be added to the appliance and the following error was displayed: "Unable to activate certificate Certificate name 'XXXXX' fails to meet minimum requirements for web server.;Signature algorithm is not sha-256, sha-384, sha-512, or better". This issue has been resolved. |
WEBUI-14478 | The Blind Command Injection vulnerability has been resolved. |
COM-30386 | The HTTP request smuggling vulnerability described in CWE-444 has been resolved. |
COM-30387 | The DOM-based Ajax request header manipulation vulnerability described in CWE-116 has been resolved. |
FMPS-2683 | The continuous scan of an Office 365 OneDrive terminated abruptly on File Protect appliances upgraded to version 9.1.2 and the following message was displayed: "Failed to" query Office 365 for changes". This issue has been resolved. |
FMPS-2693 | The AWS CloudFormation template could not be downloaded from the Storage window. This issue has been resolved. |
FMPS-2679 | The continuous scan did not resume even though the storage share came back online, hence the scans were stuck in the paused state. This issue has been resolved. |
Known issues
The following issues are known in the File Protect 9.1.4 release.
Tracking number | Summary |
|---|---|
WEBUI-14501 | A managed virtual File Protect sensor integrated with Detection-as-a-Service (DaaS) displays "Sensor Un-Enrolled" in the appliance details page. |
Technical support
For technical support, contact Trellix through the Support portal:
https://www.trellix.com/en-us/support.html
Documentation
Documentation for all Trellix products is available on the Trellix Documentation Portal: