The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure for vulnerability issues

Prev Next

It is recommended that you configure your Manager server to fix the following vulnerability issues:

Vulnerability message

Port

Configuration Changes

X.509 Certificate Subject CN Does Not Match the Entity

Name (certificate-common-name-mismatch)

NA

Replace self-signed SSL certificate with a CA-signed SSL certificate.

SMB signing disabled (cifs-smb-signing-disabled)

SMB signing not required (cifs-smb-signing-not-required)

NA

Configure SMB signing for Windows. SMB signing is enabled on the server side if the following conditions are true:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Lanmanserver\Parameters\Enablesecuritysignature registry value is set to 1,or if the corresponding Group Policy setting is enabled.

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Lanmanserver\Parameters\Requiresecuritysignature registry value is set to 0,or if the corresponding Group Policy setting is disabled.

TLS/SSL Birthday attacks on 64-bit block ciphers (SWEET32)

(ssl-cve-2016-2183-sweet32)

NA

  • Remove the TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher as it is insecure.

  • Disable support for TLSv1.0 & TLSv1.1

TLS/SSL Server Supports RC4 Cipher Algorithms

(CVE-2013-2566) (rc4-cve-2013-2566)

NA

  • Remove the TLS_RSA_WITH_RC4_128_MD5 and the TLS_RSA_WITH_RC4_128_SHA ciphers as they are insecure.

  • Disable support for TLSv1.0 & TLSv1.1

TLS/SSL Server Supports The Use of Static Key Ciphers (ssl-static-key-ciphers)

NA

  • Remove the following insecure ciphers as they are insecure.

    TLS 1.0 ciphers:

    • TLS_RSA_WITH_3DES_EDE_CBC_SHA

    • TLS_RSA_WITH_AES_128_CBC_SHA

    • TLS_RSA_WITH_AES_256_CBC_SHA

    • TLS_RSA_WITH_RC4_128_MD5

    • TLS_RSA_WITH_RC4_128_SHA

    TLS 1.1 ciphers:

    • TLS_RSA_WITH_3DES_EDE_CBC_SHA

    • TLS_RSA_WITH_AES_128_CBC_SHA

    • TLS_RSA_WITH_AES_256_CBC_SHA

    • TLS_RSA_WITH_RC4_128_MD5

    • TLS_RSA_WITH_RC4_128_SHA

    TLS 1.2 ciphers:

    • TLS_RSA_WITH_3DES_EDE_CBC_SHA

    • TLS_RSA_WITH_AES_128_CBC_SHA

    • TLS_RSA_WITH_AES_128_CBC_SHA256

    • TLS_RSA_WITH_AES_256_CBC_SHA

    • TLS_RSA_WITH_AES_256_CBC_SHA256

    • TLS_RSA_WITH_RC4_128_MD5

    • TLS_RSA_WITH_RC4_128_SHA

  • Disable support for TLSv1.0 & TLSv1.1

TLS Server Supports TLS version 1.1 (tlsv1_1-enabled)

NA

Disable support for TLSv1.0 & TLSv1.1

Diffie-Hellman group smaller than 2048 bits (tls-dh-prime-under-2048-bits)

Na

  • Remove the following insecure ciphers as they are insecure.

    TLS 1.0 ciphers:

    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA with a Diffie-Hellman prime modulus of 1024 bits

    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA with a Diffie-Hellman prime modulus of 1024 bits

    TLS 1.1 ciphers:

    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA with a Diffie-Hellman prime modulus of 1024 bits

    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA with a Diffie-Hellman prime modulus of 1024 bits

  • Disable support for TLSv1.0 & TLSv1.1

TLS/SSL Server Is Using Commonly Used Prime Numbers (tls-dh-primes)

NA

Disable support for TLSv1.0 & TLSv1.1

ICMP timestamp response (generic-icmp-timestamp)

443

8501

8502

8503

8506

8507

8508

Enable Windows firewall and disable the ICMP timestamp response. To do this, perform the following steps:

  1. Enable the windows firewall by selecting the on (recommended) option.

  2. Open a command prompt and enter netsh firewall set icmpsetting 13 disable

  3. Allow inbound and outbound communication on port 443 and all the ports used by the Manager to communicate with outside devices like Sensors, ePO, and so on. For communicating with the Sensor, the Manager uses ports 8501-8503 and 8506-8508.

Caution

If you do not create firewall rules with proper port information, applying this solution might break your existing communication.

TLS/SSL Server Supports 3DES Cipher Suite (ssl-3des-ciphers)

NA

  • Remove the following insecure ciphers as they are insecure.

    TLS 1.0 ciphers:

    • TLS_RSA_WITH_3DES_EDE_CBC_SHA

    TLS 1.1 ciphers:

    • TLS_RSA_WITH_3DES_EDE_CBC_SHA

    TLS 1.2 ciphers:

    • TLS_RSA_WITH_3DES_EDE_CBC_SHA

  • Disable support for TLSv1.0 & TLSv1.1

SSL Certificate Signed Using Weak Hashing Algorithm

3389

Contact the Certificate Authority to issue a certificate signed with strong hashing algorithm.

Note

  • The exact vulnerability message might differ based on the Vulnerability Scanner you use.

  • Most of the configuration changes require changes to the Windows registry and you should be careful when changing the registry values. For general information on changing the Windows registry values, see the Microsoft Knowledge Base article 310516.