If you are upgrading the Manager from version 10.1 or 11.1 to version 11.1.7.84, read the following sections carefully.
Attack being mapped to multiple tactics, techniques, and sub-techniques in the Attack Log
Starting with this release of 11.1, if an attack matches with multiple tactics, techniques, and/or sub-techniques, their names along with applicable technique/sub-technique IDs are shown in the respective fields under the Mitre Attack Details column in the → → page. You can also view the same details by double-clicking an attack.
When an attack is mapped to multiple tactics, techniques, and/or sub-techniques, there is one-to-one correspondence among the tactics, techniques, sub-techniques, and technique/sub-technique IDs. For example, the first tactic corresponds to the first technique, sub-technique, technique/sub-technique ID, and so on.
Sending HTTP2 metadata to Trellix Network Investigator
Starting with this release of 11.1, IPS Sensors support the export of HTTP2 metadata to Trellix Network Investigator when the integration between Trellix IPS and Trellix NI is enabled.
Note
The NS-series Sensors NS9500, NS7600, NS7500, and NS3600 supports HTTP2 traffic inspection.
Configure the Linux-based Manager with IPv6 address
Starting with this release of 11.1, you will be able to configure the Linux-based Manager with an IPv6 address on the eth0 network interface.
The following commands are added:
Command | Description |
|---|---|
| This command is used to assign the IPv6 address for the Manager server. |
| This command is used to gather network related information as well as perform network operations. |
| This command allows you to perform various operations on the system network Manager such as start, stop, restart, and others. |
Support for Gateway Anti-Malware version 2023
With this release of 11.1, the Gateway Anti-Malware engine running on NS-series Sensors can be upgraded to version 2023. The upgraded engine offers improved stability and performance. Users also have the option to enable or disable behavioral scans on the GAM engine. This version of Gateway Anti-Malware is supported on Manager version 11.1.7.83 and later, and Sensor version 11.1.5.84 and later.
To view the Gateway Anti-Malware version in the Manager, go to → → → , click the tab, and select a Sensor from the list. The Gateway Anti-Malware version for the selected Sensor can be seen under the Protections column.
IPS Security Vulnerability updates
This release contains the fixes for the following security vulnerabilities in the IPS Manager. You must upgrade both the IPS Manager and IPS Central Manager to the 11.1.7.84 version.
CVE # | Severity | Description |
|---|---|---|
CVE-2024-5671 | High | Insecure deserialization in some IPS Manager workflows allows unauthenticated remote attackers to execute arbitrary code and access the vulnerable Trellix IPS Manager. |
CVE-2024-5731 | High | This vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to manipulate the destination of the request by altering the IP Address parameter in the request. Additionally, the request parameter contains an encoded string with the username and password, which can be decoded to obtain the original string. |
This release provides the following enhancements related to platforms, environments, or operating systems:
MariaDB upgrade
Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.6.16 which includes additional security against new vulnerabilities and bug fixes.
JDK upgrade
Starting with this release of 11.1, the IPS Manager uses JDK version 1.8u401-b03 which includes additional security against new vulnerabilities.
Apache Tomcat server upgrade
Starting with this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.85. This server update provides a collection of security fixes.
OpenSSL upgrade
Starting with this release of 11.1, the OpenSSL version is upgraded to 1.0.2zh-fips. This new version includes additional security against new vulnerabilities.