The current release of the product resolves these issues. For a list of issues fixed in earlier releases, see the Release Notes for the specific release.
For a list of current known issues, see: Trellix IPS 11.1 Known Issues (KB96274).
Resolved Manager software issues
The following table lists the high-severity Manager software issues:
|
Reference # |
Resolution |
|---|---|
|
NSPMGR-28918 |
The system creates duplicate entries for background task logs, with the User Name field remaining empty for custom users. This results in two entries per event: one blank entry for the custom user and another for the Administrator. |
The following table lists the medium-severity Manager software issues:
|
Reference # |
Resolution |
|---|---|
|
NSPMGR-29193 |
The Faults report output differs when the language is set to English or Japanese. |
|
NSPMGR-29166 |
The Quarantine Attacker option can incorrectly enable for component attacks, causing Sensors to block traffic without displaying quarantine information in the Manager. |
|
NSPMGR-29159 |
The Manager allows you to type the |
|
NSPMGR-29158 |
The Manager fails to prevent the CSV injection while exporting the rule objects data to CSV, leading to payload execution. |
|
NSPMGR-29157 |
HTTP Strict Transport Security (HSTS) is implemented with the includeSubDomains flag, but lacks the preload flag. While includeSubDomains enhances security, its use without preload increases the risk of cookie-related vulnerabilities. |
|
NSPMGR-29156 |
When editing a user's password via Manager → <Admin Domian Name> → Users → Roles → My Account, the system allows modifying the LoginID to an already existing LoginID. This results in two user accounts appearing in the GUI with the same LoginID, and both users are unable to log in. |
Resolved Sensor software issues
The following table lists the medium-severity Sensor software issues:
|
Reference # |
Resolution |
|---|---|
|
NSPSNSR-17010 |
[NS9600, NS9500, NS7600, NS7500, NS3600] The ARP packet content is overwritten, resulting in ARP packet corruption and an outage. |
|
NSPSNSR-16998 |
[NS3600] Ping requests fail on ports 5 and 6. |
|
NSPSNSR-16739 |
[NS7500] Sensors reboots unexpectedly. This issue occurred without a clear cause, interrupting sensor operations and potentially affecting network monitoring and security. |
|
NSPSNSR-16609 |
When a Sensor in an HA pair is upgraded, its failover status displays as Down when viewed using the |
|
NSPSNSR-16550 |
After a Sensor upgrade, multiple "GTI: Risky URL Detected" alerts are observed. This occurs when the DNS configuration is disabled at the device level and enabled only at the global level. |
|
NSPSNSR-16544 |
[NS3600] In an HA configuration, Port 6 displays a Port Certification Mismatch error even when this port is not in use. |
|
NSPSNSR-15992 |
When L7 data collection is disabled, the Source IP value in Syslog incorrectly changes to the Source IP Proxy value. This altered behavior continues even after L7 data collection is re-enabled, leading to persistent inaccuracies in reported Source IP addresses within syslog entries. |