Intelligent Virtual Execution - Server 10.0.4 Release Notes

Prev Next

New features and changes

  • CC-NDcPP-compliant IVX customers must reapply Compliance mode on VX appliances after upgrading to 10.0.4 to disable the VX WebUI. Other Customers are not impacted.

    Customers who choose to use the VX WebUI without formal compliance can subsequently configure by enabling it using the new CLI command web webui enable (available only on VX). For more information, see FIPS 140-2 & Common Criteria Addendum document.

Resolved issues

The following issues were resolved in the Intelligent Virtual Execution - Server 10.0.4 release.

Tracking number

Summary

VX-2853

Fixes an issue where riskware rule could not be disabled using the CLI.

COM-31727

To mitigate the Terrapin Vulnerability (CVE-2023-48795), the chacha20 cipher is removed from our high-security list for non-FIPS/non-CC customers using the high-security list. Now, the Trellix platform is not vulnerable to Terrapin Vulnerability (CVE-2023-48795) with default configuration. We plan to upgrade to the latest stable version of OpenSSH in the upcoming 11.0 major release to further harden and resolve the vulnerable option related to the Terrapin Vulnerability.

COM-62557

To further harden the security of our products, we have upgraded Apache HTTPd to version 2.4.62, the latest stable release.

Known issues

The following issues are known in the Intelligent Virtual Execution - Server 10.0.4 release.

Tracking number

Summary

VX-2615

Enabling broker role on new or upgraded cluster appliances takes cluster to degraded state. Cluster stabilizes in 10 minutes with autorecovery.

Upgrade support

The Trellix Intelligent Virtual Execution - Server 10.0.4 release requires a reboot for the update to take effect. You can upgrade your IVX appliance to 10.0.4 from release 9.0.0 or later.

Note

You can upgrade Intelligent Virtual Execution - Server appliances to 10.0.4 only if they are standalone nodes. For information on upgrading MVX clusters (MVX Smart Grid), see Upgrading MVX Clusters on the next page.

Note

After an upgrade to version 10.0.0, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Upgrading MVX clusters

Direct upgrade of MVX clusters (MVX Smart Grid) from a pre-9.1.0 release to 10.0.4 is not supported. Follow the procedure in this Community article to upgrade your MVX clusters.

Note

To upgrade 9.1.x MVX clusters, you must first upgrade the CMS to version 10.0.2.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.

Downloading content from the DTI offline update portal

If you download Intelligent Virtual Execution - Server 10.0.4 security content from the DTI Offline Update Portal, use the SCCMS-3.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the

Trellix DTI Offline Update Portal User Guide

.

YARA rules supported versions

Before you upgrade an Intelligent Virtual Execution - Server appliance to the 10.0.1 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.