Trellix Enterprise Security Manager 11.6.14 addresses known issues.
This release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.14
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.
Upgrade considerations
Trellix ESM 11.6.x and higher do not support environments configured with distributed Trellix ESM. See Upgrade HA receivers to upgrade to 11.6.x version for the first time.
New or changed
You can now apply a filter before you export device summary reports. On the View Reports page, a new tab called Device Status lists all datasources and their status. Select the checkbox to include all datasources, only those that are enabled, or only those that are disabled when you export the device summary report.
You can now save ELM backup files in the ELM device itself.
Resolved issues
This release provides resolution for the following issues.
Category | Reference | Resolution |
|---|---|---|
Datasources | SIEM-26751 | Fixed an issue when exporting data sources that caused the fields enabled and parsing to be excluded. |
ESM device | SIEM-37052 | Fixed an issue that caused sub-menus not to display when you hovered over them. |
ERC device | SIEM-39664 | Fixed an issue retrieving a vulnerability report on a connected Nexpose Rapid7 VA. |
Correlation | SIEM-39795 | Fixed an issue that caused rules to break when using the dollar sign ($) in regular expressions. |
User interface | SIEM-39887 | Fixed an issue with port allocation that caused excessive errors on the Trellix ESM device log. |
Alarms | SIEM-40019 | Fixed an issue that caused acknowledged alarms to display the incorrect date format. |
API | SIEM-40096 | Fixed an issue that caused the zoneGetSubZone API to return empty fields. |
User interface | SIEM-40156 | Fixed an issue that caused reports using a bar chart and saved in HTML format not to be generated. |
User Interface | SIEM-40186 | Fixed an issue that caused the cursor to not automatically move to the selected data source after searching for a data source. |
User interface | SIEM-40216 | Fixed an issue that caused the Device Summary Reports event time field to take an excessive time to populate when using a web browser. |
User interface | SIEM-40225 | Fixed an issue that caused you to be unable to set the color of the boarder or font in reports. |
Software upgrade | SIEM-40259 | Updated javascript and tomcat to address CVE-2018-20801, CVE-2019-10744, CVE-2022-25844, and CVE-2023-46589. |
ERC device | SIEM-40273, SIEM -40285 | Fixed an issue that caused healthmon not to get the status of kafka. |
ELM device | SIEM-40279 | Fixed an issue that caused the Storage Pool page to be unresponsive when accessed using a web browser. |
ESM device | SIEM-40280, SIEM-40293 | Fixed an issue that caused CRL validation to fail when a new certificate file was uploaded to Trellix ESM if there was an existing certificate. |
HA receiver | SIEM-40312 | Fixed an issue that caused logs collected and parsed on Cisco Firepower Management Center - eStreamer to display the incorrect first time and last time. |
Correlation | SIEM-40314 | Fixed an issue that caused no correlated events to appear in the dashboard after updating from 11.6.9 to 11.6.13. |
Policy rollout | SIEM-40328 | Fixed an issue that caused inconsistent errors when manually rolling out policies to all devices after updating from 11.6.12 to 11.6.13. |
Middleware | SIEM-40368 | Fixed an issue that caused the NGCP password change script to fail to update the password when executed through cronjob. |
Correlation | SIEM-40369 | Fixed an issue with errors seen in correlation logs when alarms were triggered inconsistently. |
This release provides resolution for the following content issues through a rule update.
Category | Reference | Resolution |
|---|---|---|
3rd party ASP rules | SIEM-40260 | Rule 43-471020970 has been added to parse the following Windows Defender Firewall fields: ModifyingApplication, ModifyingUser, RuleName, Direction,Protocol, LocalPorts, and Action. |
3rd party ASP rules | SIEM-40276 | Updated parsing rules 1068944 to 1068979 to fix an issue that prevented parsing of Skyhigh Secure Webgateway logs. |
3rd party ASP rules | SIEM-40329 | Due to issues parsing Trellix IPS logs, the log format has been changed. |
Known issues
For a list of known issues in this product release, see KB90422.