Resolved issues

Prev Next

The following issues were resolved in the Central Management System 10.0.0 release.

Tracking number

Summary

CMS-16158

Testfire events did not appear in the alerts tab for Malware Object, Malware Callback, Domain Match, Infection Match, and Web Infection alerts. This issue is resolved.

CMS-16320

An upgrade to version 9.0.1 resulted in a slow email search. This issue is resolved.

CMS-16346

Squid check was triggered when the Central Management System appliance was in offline mode. This issue is resolved.

CMS-16369

After an upgrade to version 9.1.0, the CMSHA Fedb Sync health service was disabled. This issue is resolved

CMS-16501

The mgmtd.ERR error messages were displayed while creating a cluster. This issue is resolved.

CMS-16550

The malicious URLs in the static report were not rewritten. This issue is resolved.

CMS-16587

The alert ID on the Analysis page was clickable even though the analysis was active. This issue is resolved.

CMS-16591

The performance of get_unprocessed_ips_events was lacking due to a missing index. This issue is resolved.

CMS-16612

Offline appliances could not download Security Content updates from the Central Management System appliance. This issue is solved.

CMS-16691

The Central Management System appliance delayed sending the IPS logs to the SIEM via syslog. This issue is resolved.

CMS-16699

The alert notification configuration change was not applied immediately. This issue has been fixed by refreshing the alert notification service upon configuration change.

CMS-16718

Alert aggregation on Central Management System appliance failed due to UnicodeDecodeError. This issue is resolved.

CMS-16732

The URL in the alerting email had the SSH address of the Cloud Central Management System instead of the web UI address. The alert did not load as expected. This issue is resolved.

CMS-16764

The Email Security - Cloud alert IOC generated from the Central Management System appliance had an incorrect alert URL. The UUID format is now used in the alert URL

CMS-16813

Email Security — Server alert aggregation failed for one or more sensors. This issue is resolved.

CMS-16823

The Central Management System appliance did not generate reports when one of the reports had a huge amount of alerts in a short period. This issue is resolved.

CMS-16836

The "UnboundLocalError" was displayed during alert report generation. This issue is resolved.

CMS-16866

A syslog notification issue was observed in the CM 7500 appliance for EX testfire alerts. This issue is resolved.

CMS-16872

After an upgrade, the notification messages were not cleared even after the review. This issue is resolved.

CMS-16967

Scheduled generation of large reports caused an out-of-memory issue. This issue. This issue is resolved by restricting the size of the report.

CMS-16998

Some Email Security - Cloud alerts failed to aggregate to the Central Management System due to a double-byte characters issue. This issue is resolved.

CMS-17046

In some cases, the IPS events generated on the Network Security appliance did not have CVE ID but the same event on the Central Management System appliance displayed the CVE ID. This issue is resolved.

CMS-17073

Although the data retention was enabled on the Central Management System appliance, the data retention failed due to the failure of the purge process. This issue is resolved.

CMSHA-1434

In CMS-HA configuration, changing the hostname of a node resulted in cluster formation with the current hostname and previous hostname. This issue is resolved.

CMSHA-1514

The CMS-HA failover failed and issues were noticed in the database backup of the secondary appliance in the HA cluster. This issue is resolved.

COM-12986

New logs could not be generated due to the Log Manager Create button being disabled and the progress showed "Archive being created". The issues are resolved.

COM-23960

The physical disk serial number did not match the output of show media disk. This issue is resolved.

COM-29773

Upgrading previously created certs under FireEye org name is not supported.

COM-29863

Apache has been upgraded to overcome the vulnerability described in IAVM 2022-A-0124.

COM-29874

Vulnerabilities CVE-2022-22965, CVE-2022-22963, and CVE-2022-22950 are resolved.

COM-29002

The show log continuous command was not generating the expected output. The issue is resolved.

COM-29377

The Velocity Engine has been upgraded to address the Velocity Sandbox Bypass issue (CVE-2020-13936).

COM-29624

Some appliances could not connect to HelixConnect. This issue is resolved.

COM-29702

CEF logs did not have the cs6 field extension. This issue is resolved.

COM-30030

Alert notifications and alert logs were delayed when many detections occurred simultaneously. This issue is resolved.

COM-30031

The Apache vulnerability described in IAVM 2022-A-0230 has been addressed.

COM-30144

The SMTP alerts using TLS failed to authenticate if the password contained a # character. This issue is resolved.

COM-30244

mgmtd could not be recovered if a failure occurred. The issue is resolved. mgmtd can now be recovered by rebooting the system after a failure.

COM-30325

SNMP settings used to reset to default values on reloading the site or logging out. The issue is resolved.

COM-30344

TLS version 1.1 was not secure enough in compliance mode for CC-NDcPP 2022 certification. The issue is resolved. TLS is upgraded to version 1.2.

COM-30537

CVE-2021-46848 vulnerability has been addressed.

COM-30604

Delimiter between multiple SSH Allow users was not effective. The issue was resolved.

COM-30641

The full file path was included in the "filename" field in the metadata that was sent to cloud.fireeye.com. This issue has been resolved.

COM-30743

License update was producing the error message, "Internal error fetching licenses". The issue is resolved.

COM-30788

You can now view datastreaming logs from the CLI using the show datastreaming log command.

COM-30894

Issues of generating empty static reports have been fixed.

COM-30935

SNMPv3 allowed the creation of a user with an invalid SNMP key. This issue is resolved.

COM-30950

The original file names were being truncated in the malware analysis table during local and remote transfer. The issue is resolved.

COM-31007

Apache has been upgraded to overcome the vulnerability described in CVE-2023-24998.

COM-31187

Advanced URL Defense reported an error on the sensor appliance. The issue is resolved.

EMPS-15912

FAUDE Bottlenecks were caused when a managed appliance was connected to a Central Management System appliance. This issue is resolved.

WEBUI-14724

Naming a custom dashboard using non-ASCII and hyphen characters failed on the Web UI with the following error message: "Please enter a valid name". This issue is resolved.