Trellix Enterprise Security Manager 11.6.12 addresses known issues.
This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.12
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade considerations
Trellix ESM 11.6.x and higher do not support environments configured with distributed Trellix ESM. See Upgrade HA receivers to upgrade to 11.6.x version for the first time.
New or changed
You can now choose to configure Trellix ESM to automate importing data sources and alarms.
You can now use CLI commands to change NGCP passwords.
There is now additional validation when you use special characters in custom displays and message forwarding flows.
When you update passwords, they are now AES encrypted.
You can only create two custom displays per user per session in a two minute period of time.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
Software upgrade | SIEM-39139 | Fixed an issue with the Apache library related to CVE-2023-25690. |
ACE device | SIEM-39637 | Fixed an issue that affected correlation rules being written out. |
Middleware | SIEM-39741 | Fixed an issue that caused device details to not display when exporting a device report. |
Software upgrade | SIEM-39831 | Fixed an issue that prevented LDAP users logging in to Trellix ESM. |
ELM device | SIEM-40038 | Fixed an issue with EDSFTP to only use the ciphers, key exchange, or mac algorithms specified in the sshd_config file. |
Middleware | SIEM-40039 | Fixed an issue that caused rule messages for Windows events to start numerically, rather than with the rule name. |
Software upgrade | SIEM-40063 | Fixed an issue with the previous two versions of Trellix ESM that caused High Availability upgrades to not work. |
This release provides resolution for the following content issues through a rule update.
Category | Reference | Resolution |
|---|---|---|
3rd party ASP rules | SIEM-39974 | Updated parsing rule 1070172 to capture the right normalized ID for Microsoft Azure data source. |
3rd party ASP rules | SIEM-40015 | Added parsing rules 1070865,1070866, and 1070867 to capture source and destination IP addresses for Microsoft Azure data source. |
3rd party ASP rules | SIEM-40066 | Added parsing rule 1070877 for the Intersect Alliance Snare for Windows data source. |
Known issues
For a list of known issues in this product release, see KB90422.