The current release of the product resolves these issues. For a list of issues fixed in earlier releases, see the Release Notes for the specific release.
For a list of current known issues, see Trellix IPS 10.1 Known Issues (KB92105).
Resolved Manager software issues
The following table lists the issues that occur for alerts with negative ID in an MDR scenario during alert archival and alert pruning tasks. These issues are not reproducible in the local environment, but are resolved with code analysis:
| ID # | Issue Description |
|---|---|
| NSPMGR-22055 | Due to multiple database processes, like alert archival and DB pruning running parallelly, the Manager becomes unresponsive. |
| NSPMGR-22054 | In an MDR pair, both the Primary and Secondary Manager archives a large number of data repeatedly and runs out of available memory. |
| NSPMGR-21946 | In rare scenarios, the Manager uses high memory when file and DB pruning is scheduled after alert archival. |
| NSPMGR-20578 | In an MDR pair, the primary Manager fails to communicate with secondary Manager resulting in delayed response from the Manager interface. |
The following table lists the high-severity Manager software issues:
| Reference # | Resolution |
|---|---|
| NSPMGR-22071 | The Central Manager fails to prune alerts from Solr DB, resulting in delayed response from the Attack Log. |
| NSPMGR-18916 | DB tuning process is blocked due to a parallel thread running for alerts with negative ID in the background. |
The following table lists the medium-severity Manager software issues:
| Reference # | Resolution |
|---|---|
| NSPMGR-22143 | The Results column of Anticipated Database Disk Usage displays incorrect usage details in Manager → Admin Domain Name → Troubleshooting → Health Check. |
| NSPMGR-21998 | Discrepancy is observed in host name and IP address between the Manager Dashboard and Summary page. |
| NSPMGR-21925 | In an MDR pair, after the Manager reboot, the domain name details and unknown matched policy alerts are missing in Attack Log. |
| NSPMGR-21800 | Log4J vulnerabilities are detected in "...\App\akka\bin\jmxsh-R5.jar" file. The following are the Log4J vulnerabilities:
CVE-2021-45105 CVE-2021-45046 CVE-2021-44832 CVE-2021-44228 CVE-2021-4104 |
| NSPMGR-21182 | During device reinitialization, the deploy pending changes to device fails. This generate continues alerts in the Manager. |
| NSPMGR-21144 | The Manager displays only five latest versions of 10.1 Sensor software in Download Device Software panel. Also, during the device deployment, the Status column in Background Tasks page continues to display the status as In Progress. |
| NSPMGR-21134 | Unable to save ARP Spoofing settings in Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Layer 2 Bypass. |
| NSPMGR-20820 |
The following are the OpenJDK vulnerabilities: CVE-2022-21496 CVE-2022-21476 CVE-2022-21449 CVE-2022-21443 CVE-2022-21434 CVE-2022-21426 |
| NSPMGR-20815 | The session ID remains constant before and after logging in. This triggers vulnerability in the Manager. |
| NSPMGR-20800 | When automated DB tuning is in-progress, alerts raised during the process are not sent to the Syslog server. |
| NSPMGR-20798 | Discrepancy in alerts is observed between the Manager Dashboard and Attack Log page. |
| NSPMGR-20788 | After restoring the DB configuration, an error "Key Value not found for property DeviceLicense.CLOUD.Check.Notice in the properties file" occurs in the Manager. |
| NSPMGR-20787 | [AWS] In the Manager, root partition uses only 20 GB out of 150 GB. |
| NSPMGR-20784 | The Save Confirmation window in Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS fails to display the change for alert notification action. |
| NSPMGR-20577 | The Manager screen freezes when the IPS policies are updated in Policy → <Admin Domain Name> → Intrusion Prevention → Policy Manager. |
| NSPMGR-20333 | A condition in a custom attack, to exclude a URL fails to work. |
| NSPMGR-17643 | After reinstalling a HA pair, despite enabling the CLI Activity Logging, the User Activities fails to display the logs for primary Sensor. |
The following table lists the low-severity Manager software issues:
| Reference # | Resolution |
|---|---|
| NSPMGR-18832 | The Manager logs display an unknown Sensor ID instead of an NTBA ID. |
Resolved Sensor software issues
The following table lists the high-severity Sensor software issues:
| Reference # | Resolution |
|---|---|
| NSPSNSR-12566 | For VLAN subinterfaces, VoIP calls getting impacted due to SIP traffic drop on the Sensor after upgrade to 10.1. |
| NSPSNSR-12457 | SSL inspection causes latency when decryption happens over SSL resumption sessions. |
The following table lists the medium-severity Sensor software issues:
| Reference # | Resolution |
|---|---|
| NSPSNSR-12442 | An error "The limit of XXXX IPv4 addresses has been reached on this device" is displayed while adding quarantine entries manually to the Sensor though threshold level is not reached. |
| NSPSNSR-11705 | Contents of IV_SOURCE_IP and IV_SOURCE_PROXY_IP are interchanged in Syslog notification. |