Trellix Enterprise Security Manager 11.6.13 addresses known issues.
This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.13
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade considerations
Trellix ESM 11.6.x and higher do not support environments configured with distributed Trellix ESM. See Upgrade HA receivers to upgrade to 11.6.x version for the first time.
New or changed
You can integrate the following data sources with Trellix ESM:
ESET.
SentinelOne.
The Trellix ESM user interface has a new field called Match Missing Field. When this is selected, events without the specified field will also be considered for correlation.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
HA Receiver | SIEM-32238 | Fixed an issue that caused HA failover events to time out early. |
Software Upgrade | SIEM-33726 | Updated Azul Java to address multiple CVEs. |
Watchlists | SIEM-38940 | Fixed an issue that caused string IDs, instead of string values, to be exported from watchlists. |
Correlation | SIEM-39647 | Fixed an issue that caused information to be excluded when the NOT IN correlation was used. |
DSB Device | SIEM-39881 | Fixed an issue that caused DSB Multi Node to fail. |
User Interface | SIEM-40165 | Fixed an issue that caused VM Disc space not to display. |
Correlation | SIEM-40167 | Fixed an issue that caused ISEF parsing and correlation grouping to fail after upgrading to Trellix ESM 11.6.10. |
Software Upgrade | SIEM-40168 | Updated the libcurl version to address CVE-2023-38545 and CVE-2023-38546. |
HA Receiver | SIEM-40169 | Fixed an issue that caused an error message that said HA device toggling had failed when it had been successful. |
ELM Search | SIEM-40170 | Fixed an issue that caused packet data retrieval to fail during Enterprise Log Manager (ELM) search. |
Correlation | SIEM-40177 | Fixed an issue that caused correlation diagnostics to not show the resources that top rules were consuming. |
User Interface | SIEM-40184 | Fixed an issue that caused the cursor to reset to its starting position when searching for a device. |
User Interface | SIEM-40185 | Fixed an issue that caused Trellix ESM interfaces to remain unchecked when accessed through the browser. |
User Interface | SIEM-40186 | Fixed an issue that caused the cursor to not automatically move to the selected data source after searching for a data source. |
User Interface | SIEM-40207 | Fixed an issue with the Trellix ESM user interface where multiple devices could not be selected for report filtering. |
Correlation | SIEM-40211 | Fixed an issue that caused a correlation instance map error. |
User Interface | SIEM-40212 | Fixed an issue on the policy rollout page that contained an invalid hyperlink. |
Snow Service | SIEM-40252 | Fixed an issue to address reverse shell vulnerability related to CVE-2024-11481 and CVE-2024-11482. |
This release provides resolution for the following content issues through a rule update.
Category | Reference | Resolution |
|---|---|---|
3rd party ASP rules | SIEM-40152 | Updated parsing rules 1037448, 1046818, and 1048662 for Database Security - CEF to fix an issue that prevented parsing of DAM logs. |
3rd party ASP rules | SIEM-40166 | Updated parsing rule 1051797 to fix an issue that prevented parsing of IPS logs. |
Known issues
For a list of known issues in this product release, see KB90422.