Resolved issues

Prev Next

The current release of the product resolves these issues. For a list of issues fixed in earlier releases, see the Release Notes for the specific release.

For a list of current known issues, see:Trellix IPS 11.1 Known Issues (KB96274).

Resolved Manager software issues

The following table lists the medium-severity Manager software issues:

Reference #

Resolution

NSPMGR-28304

Authentication bypass vulnerability via a few URLs is observed in Trellix IPS Manager, that results in exception or garbage results in some cases.

NSPMGR-28077

Allow list/Block list bulk update fails when there are hash entries with file size 0.

NSPMGR-27999 NSPMGR-27961

When a proxy server is configured in which the proxy username is invalid or set with a whitespace character, the following changes are observed in Manager UI:

  • The Sync and Protections columns on the Sensors tab of the Devices <Admin Domain Name>GlobalDevice Manager page keep loading.

  • The Sync and Protections columns of the Devices <Admin Domain Name> Devices<Device name>Summary page keep loading.

  • No engine version is displayed in the Devices <Admin Domain Name>Devices<Device Name>SetupGAM Updating page.

NSPMGR-27996

A few accumulated alerts are not getting forwarded from the local Manager to the Central Manager after the trust is established and initial synchronization is completed.

NSPMGR-27993

When there is no data to be uploaded to Titan F telemetry service, it is logged as an error on the System files tab of the Manager <Admin Domain Name>TroubleshootingLogs page.

NSPMGR-27956

File name does not reflect the correct year when trying to save the attack log as PDF or CSV file from the Attack Log page.

NSPMGR-27925

Azul Zulu Java Multiple Vulnerabilities (2024-04-16) are reported by third-party vulnerability scanners in Manager running on version 11.1.7.71.

NSPMGR-27919

Database initialization error occurs after upgrading the Linux-based Manager from software version 10.1.7.65 to any software versions of 11.1 release.

NSPMGR-27905

Email IDs with domains, that include the words 'script' or 'scripts', are not accepted while adding or modifying any user details in the Manager <Admin Domain Name>Users and RolesUsers page.

NSPMGR-27880

Latest GAM engine versions show up as "---" instead of the actual version in the following paths of the Manager UI:

  • Devices <Admin Domain Name>Devices<Device Name>SetupGAM Updating page

  • The SensorsProtections column in the Devices <Admin Domain Name>GlobalDevice Manager page

NSPMGR-27879

Even after configuring a custom email message with $IV_QUARANTINE_END_TIME variable for IPS events in the Manager, quarantine information for the variable does not show up in email notifications.

NSPMGR-27874

Sensor name is getting truncated under Devices <Admin Domain Name> Devices<Device Name> drop down menu after upgrading to Manager software version 11.1.7.56.

NSPMGR-27843

The Manager keeps sending IPS events with TCP connections to Syslog server even when the server (TCP client) is closed or down.

NSPMGR-27832

The iv.core.perfmon.dbcoordinator logger level configuration in Log4j2.xml causes alertdbcoord.log file to overgrow in size and affect disk space.

NSPMGR-27548

Sync Status field shows as "---" instead of proper status text in synchronization failure scenarios in the following paths in Manager UI:

  • Devices <Admin Domain Name> Devices<Device name>Summary page

  • On the Sensors tab in Devices <Admin Domain Name>GlobalDevice Manager page

NSPMGR-27534

Error message in the Manager UI displayed for exceeding CIDRs exclusion count for GTI Reputation lookup incorrectly mentions Allow list limit.

NSPMGR-27519

Auto-assignment fails to assign the license to a newly added Sensor in an existing cluster, despite free licenses being available in the pool.

NSPMGR-27403

The Member Sensors hyperlink in the vIPS Clusters tab fails to redirect the Sensors to the specific cluster when accessed from child domain.

NSPMGR-27363

Few Central Manager IPS policies show up as deleted in the local Manager when being assigned to any Sensor.

NSPMGR-27204

Running NSM-SDK-API header with invalid encoded value via any REST API client fetches valid responses.

NSPMGR-22692

After you upgrade the Sensor, the Device Manager page still displays the previous Sensor version.

NSPMGR-17563

You cannot enter more than two characters in the Search attack name field of the Policy <Admin Domain Name> Intrusion PreventionExceptionsIgnore Rules page.

Resolved Sensor software issues

The following table lists the high-severity Sensor software issues:

Reference #

Resolution

NSPSNSR-15807

In some rare cases, when Sensor-Manager communication over SNMP port 8500 fails, the alert channel flaps and causes Sensor to show as Trust Pending in the Manager due to incorrect error handling at SNMPD process.

The following table lists the medium-severity Sensor software issues:

Reference #

Resolution

NSPSNSR-15854

NSPSNSR-15774

With XFF enabled, the Source Proxy IP is sent to Syslog instead of Source IP for suppressed alerts.

NSPSNSR-13496

Small TCP window length in Sensor leads to packets being erroneously dropped.