The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Notes for upgrading the Manager from 10.1 or 11.1 to 11.1.19.11

Prev Next

If you are upgrading the Manager from version 10.1 or 11.1 to version 11.1.19.11, read the following sections carefully.

Attack being mapped to multiple tactics, techniques, and sub-techniques in the Attack Log

Starting with this release of 11.1, if an attack matches with multiple tactics, techniques, and/or sub-techniques, their names along with applicable technique/sub-technique IDs are shown in the respective fields under the Mitre Attack Details column in the Analysis → <Admin Domain Name> → Attack Log page. You can also view the same details by double-clicking an attack.

When an attack is mapped to multiple tactics, techniques, and/or sub-techniques, there is one-to-one correspondence among the tactics, techniques, sub-techniques, and technique/sub-technique IDs. For example, the first tactic corresponds to the first technique, sub-technique, technique/sub-technique ID, and so on.

Sending HTTP2 metadata to Trellix Network Investigator

Starting with this release of 11.1, IPS Sensors support the export of HTTP2 metadata to Trellix Network Investigator when the integration between Trellix IPS and Trellix NI is enabled.

Note

The NS-series Sensors NS9500, NS7600, NS7500, and NS3600 supports HTTP2 traffic inspection.

Configure the Linux-based Manager with IPv6 address

Starting with this release of 11.1, you will be able to configure the Linux-based Manager with an IPv6 address on the eth0 network interface.

The following commands are added:

Command

Description

set network ipv6

This command is used to assign the IPv6 address for the Manager server.

nmcli

This command is used to gather network related information as well as perform network operations.

networkmanager

This command allows you to perform various operations on the system network Manager such as start, stop, restart, and others.

Support for Gateway Anti-Malware version 2023

With this release of 11.1, the Gateway Anti-Malware engine running on NS-series Sensors can be upgraded to version 2023. The upgraded engine offers improved stability and performance. Users also have the option to enable or disable behavioral scans on the GAM engine. This version of Gateway Anti-Malware is supported on Manager version 11.1.19.11 and later, and Sensor version 11.1.17.13/11.1.17.14 and later.

To view the Gateway Anti-Malware version in the Manager, go to Devices → <Admin Domain Name> → Global → Device Manager, click the Sensors tab, and select a Sensor from the list. The Gateway Anti-Malware version for the selected Sensor can be seen under the Protections column.

IPS Security Vulnerability updates

This release contains the fixes for the following security vulnerabilities in the IPS Manager. You must upgrade both the IPS Manager and IPS Central Manager to the 11.1.19.11 version.

Security Vulnerability details

CVE #

Severity

Description

CVE-2024-5671

High

Insecure deserialization in some IPS Manager workflows allows unauthenticated remote attackers to execute arbitrary code and access the vulnerable Trellix IPS Manager.

CVE-2024-5731

High

This vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to manipulate the destination of the request by altering the IP Address parameter in the request. Additionally, the request parameter contains an encoded string with the username and password, which can be decoded to obtain the original string.



This release provides the following enhancements related to platforms, environments, or operating systems:

MariaDB upgrade

Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.6.16 which includes additional security against new vulnerabilities and bug fixes.

JDK upgrade

Starting with this release of 11.1, the IPS Manager uses JDK version 1.8u401-b03 which includes additional security against new vulnerabilities.

Apache Tomcat server upgrade

Starting with this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.85. This server update provides a collection of security fixes.

OpenSSL upgrade

Starting with this release of 11.1, the OpenSSL version is upgraded to 1.0.2zh-fips. This new version includes additional security against new vulnerabilities.